mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
28 lines
1.5 KiB
YAML
28 lines
1.5 KiB
YAML
name: Ransomware
|
|
id: cf309d0d-d4aa-4fbb-963d-1e79febd3756
|
|
version: 1
|
|
date: '2020-02-04'
|
|
description: Leverage searches that allow you to detect and investigate unusual activities
|
|
that might relate to ransomware--spikes in SMB traffic, suspicious wevtutil usage,
|
|
the presence of common ransomware extensions, and system processes run from unexpected
|
|
locations, and many others.
|
|
narrative: Ransomware is an ever-present risk to the enterprise, wherein an infected
|
|
host encrypts business-critical data, holding it hostage until the victim pays the
|
|
attacker a ransom. There are many types and varieties of ransomware that can affect
|
|
an enterprise. Attackers can deploy ransomware to enterprises through spearphishing
|
|
campaigns and driveby downloads, as well as through traditional remote service-based
|
|
exploitation. In the case of the WannaCry campaign, there was self-propagating wormable
|
|
functionality that was used to maximize infection. Fortunately, organizations can
|
|
apply several techniques--such as those in this Analytic Story--to detect and or
|
|
mitigate the effects of ransomware.
|
|
author: David Dorsey, Splunk
|
|
type: ESCU
|
|
references:
|
|
- https://www.carbonblack.com/2017/06/28/carbon-black-threat-research-technical-analysis-petya-notpetya-ransomware/
|
|
- https://www.splunk.com/blog/2017/06/27/closing-the-detection-to-mitigation-gap-or-to-petya-or-notpetya-whocares-.html
|
|
tags:
|
|
analytics_story: Ransomware
|
|
usecase: Advanced Threat Detection
|
|
category:
|
|
- Malware
|