Here's the continuation

More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
🤔 Remember, in a couple of previous posts we described simple and slightly more complex approaches to detecting malware using the example of an email that landed in our SOC and an attachment from it?
Here’s the continuation 👇
If a similar malware managed to get past all the lines of defense, land on a user’s machine, and start working there, not all is lost!
You did notice that at the first stage the malicious BAT file copied and renamed a couple of system files (cmd.exe and certutil.exe), which it then used?
Detecting such behavior is easy to automate 😏
A well-configured Microsoft Sysmon service allows you not only to log process launches and command-line parameters, but also to capture such interesting data from file properties as its original name (see screenshots 1 and 2).
Which means it’s enough to simply compare the values of two fields in an event to detect the use of this hacking technique in time (it’s called “Masquerading: Rename System Utilities“, by the way).
As part of the MaxPatrol SIEM expertise packages, we have a rule for this case as well — Copied_or_Renamed_Executable.
And if you don’t have our product, you can use one of the SIGMA rules proc_creation_win_renamed_binary_highly_relevant as a basis for your detections.

#Detect #Sigma #Rules
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…







