[ << ALL_FEED ]

Here's the continuation

More in General

🤔 Remember, in a couple of previous posts we described simple and slightly more complex approaches to detecting malware using the example of an email that landed in our SOC and an attachment from it?

Here’s the continuation 👇

If a similar malware managed to get past all the lines of defense, land on a user’s machine, and start working there, not all is lost!

You did notice that at the first stage the malicious BAT file copied and renamed a couple of system files (cmd.exe and certutil.exe), which it then used?

Detecting such behavior is easy to automate 😏

A well-configured Microsoft Sysmon service allows you not only to log process launches and command-line parameters, but also to capture such interesting data from file properties as its original name (see screenshots 1 and 2).

Which means it’s enough to simply compare the values of two fields in an event to detect the use of this hacking technique in time (it’s called “Masquerading: Rename System Utilities“, by the way).

As part of the MaxPatrol SIEM expertise packages, we have a rule for this case as well — Copied_or_Renamed_Executable.

And if you don’t have our product, you can use one of the SIGMA rules proc_creation_win_renamed_binary_highly_relevant as a basis for your detections.

#Detect #Sigma #Rules
@ptescalator

More from global_author

More from global_author

More in General