Files
splunk-security_content/detections/endpoint/disable_windows_behavior_monitoring.yml
2024-06-05 21:05:06 +00:00

81 lines
3.6 KiB
YAML

name: Disable Windows Behavior Monitoring
id: 79439cae-9200-11eb-a4d3-acde48001122
version: 6
date: '2024-05-18'
author: Steven Dick, Teoderick Contreras, Splunk
status: production
type: TTP
description: The following analytic identifies modifications in the registry to disable
Windows Defender's real-time behavior monitoring. It leverages data from the Endpoint.Registry
data model, specifically monitoring changes to registry paths associated with Windows
Defender settings. This activity is significant because disabling real-time protection
is a common tactic used by malware such as RATs, bots, or Trojans to evade detection.
If confirmed malicious, this action could allow an attacker to execute code, escalate
privileges, or persist in the environment without being detected by antivirus software.
data_source:
- Sysmon EventID 12
- Sysmon EventID 13
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry
WHERE (Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time
Protection\\DisableBehaviorMonitoring" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows
Defender\\Real-Time Protection\\DisableOnAccessProtection" OR Registry.registry_path=
"*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable"
OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time
Protection\\DisableRealtimeMonitoring" OR Registry.registry_path= "*\\Real-Time
Protection\\DisableIntrusionPreventionSystem" OR Registry.registry_path= "*\\Real-Time
Protection\\DisableIOAVProtection" OR Registry.registry_path= "*\\Real-Time Protection\\DisableScriptScanning"
AND Registry.registry_value_data = "0x00000001") BY _time span=1h Registry.dest
Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name
Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`
| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `disable_windows_behavior_monitoring_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the registry value name, registry path, and registry value data from your
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
Sysmon TA. https://splunkbase.splunk.com/app/5709
known_false_positives: admin or user may choose to disable this windows features.
references:
- https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html
tags:
analytic_story:
- Azorult
- Ransomware
- Windows Registry Abuse
- RedLine Stealer
- Windows Defense Evasion Tactics
- CISA AA23-347A
- Revil Ransomware
asset_type: Endpoint
confidence: 100
impact: 40
message: Windows Defender real time behavior monitoring disabled on $dest
mitre_attack_id:
- T1562.001
- T1562
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.dest
- Registry.registry_value_name
- Registry.registry_key_name
- Registry.registry_path
- Registry.registry_value_data
- Registry.process_guid
risk_score: 40
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog