Files
splunk-security_content/dev/endpoint/disable_windows_behavior_monitoring.yml
T
2023-01-20 13:24:15 +01:00

71 lines
2.9 KiB
YAML

name: Disable Windows Behavior Monitoring
id: 79439cae-9200-11eb-a4d3-acde48001122
version: 2
date: '2022-01-27'
author: Teoderick Contreras, Splunk
status: production
type: TTP
description: This search is to identifies a modification in registry to disable the
windows denfender real time behavior monitoring. This event or technique is commonly
seen in RAT, bot, or Trojan to disable AV to evade detections.
data_source:
- Sysmon Event ID 13
search:
selection1:
Details: '0x00000001'
TargetObject:
- '*\\Real-Time Protection\\DisableScriptScanning'
- '*\\Real-Time Protection\\DisableIOAVProtection'
- '*\\Real-Time Protection\\DisableIntrusionPreventionSystem'
- '*\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableRealtimeMonitoring'
- '*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable'
- '*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection'
- '*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring'
condition: selection1
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure
that this registry was included in your config files ex. sysmon config to be monitored.
known_false_positives: admin or user may choose to disable this windows features.
references:
- https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Ransomware
- Revil Ransomware
- Windows Registry Abuse
- Azorult
asset_type: Endpoint
confidence: 100
impact: 40
message: Windows Defender real time behavior monitoring disabled on $dest
mitre_attack_id:
- T1562.001
- T1562
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 40
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log
source: WinEventLog:Security
sourcetype: WinEventLog
update_timestamp: true
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log
source: WinEventLog:System
sourcetype: WinEventLog
update_timestamp: true
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog