Files
splunk-security_content/stories/ransomware.yml
Patrick Bareiss 7cbc9a9ba6 WIP
2020-04-30 10:34:18 +02:00

28 lines
1.5 KiB
YAML

name: Ransomware
id: cf309d0d-d4aa-4fbb-963d-1e79febd3756
version: 1
date: '2020-02-04'
description: Leverage searches that allow you to detect and investigate unusual activities
that might relate to ransomware--spikes in SMB traffic, suspicious wevtutil usage,
the presence of common ransomware extensions, and system processes run from unexpected
locations, and many others.
narrative: Ransomware is an ever-present risk to the enterprise, wherein an infected
host encrypts business-critical data, holding it hostage until the victim pays the
attacker a ransom. There are many types and varieties of ransomware that can affect
an enterprise. Attackers can deploy ransomware to enterprises through spearphishing
campaigns and driveby downloads, as well as through traditional remote service-based
exploitation. In the case of the WannaCry campaign, there was self-propagating wormable
functionality that was used to maximize infection. Fortunately, organizations can
apply several techniques--such as those in this Analytic Story--to detect and or
mitigate the effects of ransomware.
author: David Dorsey, Splunk
type: ESCU
references:
- https://www.carbonblack.com/2017/06/28/carbon-black-threat-research-technical-analysis-petya-notpetya-ransomware/
- https://www.splunk.com/blog/2017/06/27/closing-the-detection-to-mitigation-gap-or-to-petya-or-notpetya-whocares-.html
tags:
analytics_story: Ransomware
usecase: Advanced Threat Detection
category:
- Malware