Files
splunk-security_content/dev/endpoint/windows_diskcryptor_usage.yml
T
2023-01-20 13:24:15 +01:00

71 lines
2.3 KiB
YAML

name: Windows DiskCryptor Usage
id: d56fe0c8-4650-11ec-a8fa-acde48001122
version: 1
date: '2021-11-15'
author: Michael Haag, Splunk
status: production
type: Hunting
description: The following analytic identifies DiskCryptor process name of dcrypt.exe
or internal name dcinst.exe. This utility has been utilized by adversaries to encrypt
disks manually during an operation. In addition, during install, a dcrypt.sys driver
is installed and requires a reboot in order to take effect. There are no command-line
arguments used.
data_source:
- Sysmon Event ID 1
search:
selection1:
OriginalFileName: dcinst.exe
selection2:
Image|endswith: dcrypt.exe
condition: (selection1 or selection2)
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: It is possible false positives may be present based on the
internal name dcinst.exe, filter as needed. It may be worthy to alert on the service
name.
references:
- https://thedfirreport.com/2021/11/15/exchange-exploit-leads-to-domain-wide-ransomware/
- https://github.com/DavidXanatos/DiskCryptor
tags:
analytic_story:
- Ransomware
asset_type: Endpoint
confidence: 50
impact: 70
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ attempting to encrypt disks.
mitre_attack_id:
- T1486
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: parent_process_name
type: Process
role:
- Parent Process
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 35
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/dcrypt/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog