Files
splunk-security_content/detections/endpoint/delete_shadowcopy_with_powershell.yml
T
2021-07-21 09:22:09 +02:00

65 lines
2.2 KiB
YAML

name: Delete ShadowCopy With PowerShell
id: 5ee2bcd0-b2ff-11eb-bb34-acde48001122
version: 1
date: '2021-05-12'
author: Teoderick Contreras, Splunk
type: TTP
datamodel:
- Endpoint
description: This following analytic detects PowerShell command to delete shadow copy
using the WMIC PowerShell module. This technique was seen used by a recent adversary
to deploy DarkSide Ransomware where it executed a child process of PowerShell to
execute a hex encoded command to delete shadow copy. This hex encoded command was
able to be decrypted by PowerShell log.
search: '`powershell` EventCode=4104 Message= "*ShadowCopy*" (Message = "*Delete*"
OR Message = "*Remove*") | stats count min(_time) as firstTime max(_time) as lastTime
by EventCode Message ComputerName User | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `delete_shadowcopy_with_powershell_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the powershell logs from your endpoints. make sure you enable needed
registry to monitor this event.
known_false_positives: unknown
references:
- https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html
- https://searchwindowsserver.techtarget.com/tutorial/Set-up-PowerShell-script-block-logging-for-added-security
tags:
analytic_story:
- DarkSide Ransomware
- Ransomware
- Revil Ransomware
automated_detection_testing: passed
confidence: 90
context:
- Source:Endpoint
- Stage:Execution
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-powershell.log
impact: 90
kill_chain_phases:
- Exploitation
message: An attempt to delete ShadowCopy was performed using PowerShell on $ComputerName$
by $User$.
mitre_attack_id:
- T1490
observable:
- name: User
type: User
role:
- Victim
- name: ComputerName
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- Message
- ComputerName
- User
risk_score: 81
security_domain: endpoint