Using IoC unconventionally. Part 1. Threat hunting

More in Indicators & C2
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
- Hunting RATs by their own certificates 🕵️
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree:…
Using IoC in a non-standard way. Part 1. Threat hunting 🧐
When we talk about indicators of compromise, we usually mean a reactive approach to defense: a security tool detected a bad IP address, and we blocked it. This is certainly important, but it is dealing with the consequences.
In this post, we will discuss non-reactive scenarios for using indicators of compromise, namely — how to look for threats that have already occurred but went unnoticed, and how to use indicator data to predict future attacks.
Imagine that an attacker has already infiltrated an organization’s network and has been there for some time. They may not have used the indicators of compromise known to us, which means we missed them. What can be done about this? Well, for example, use threat hunting methods. In this case, IoCs will act not as detection signatures, but as starting points for an investigation.
As an example, let’s consider two ways of using indicators of compromise for threat hunting.
➡️ Using IoC as a basis for threat hunting
This is the most straightforward method. For example, you receive a fresh feed of indicators of compromise and see among them those related to a group you are interested in. To start, you can take only these indicators and search for their mentions in the security tool logs.
If nothing interesting is found, you should pay attention to indicators related to those you searched for earlier: it is also useful to search for them. And finally, you can use not only indicators of compromise but also indicators of attack related to them (or to the hacker group itself). It is good practice to build hypotheses based on these and verify their implementation in the security tool logs.
Example hypothesis: “A certain group uses a trojan whose executable file is often disguised as legitimate system processes. Let’s search our network for processes with names similar to dllhost.exe, svchost.exe, but launched from user temporary folders (%TEMP%, %APPDATA%), and check their hashes and network activity.”
➡️ Using IoC as a basis for building an attacker profile
Instead of searching for a specific indicator, we can look for the “signature” of a hacker group. As in the first method, we can compile a list of indicators for the group of interest and analyze their context. Often in feeds, you can find links between an indicator and MITRE ATT&CK techniques, which can hint at what kind of malicious activity an information security specialist might encounter.
Accordingly, by obtaining a list of techniques from such indicators, we can understand which threat implementation methods a particular attacker uses. Then, using the same feeds or the MITRE ATT&CK matrix, we obtain procedures for those techniques, formulate hypotheses, and test them.
Example hypothesis:
“After collecting the current set of indicators of compromise related to a certain group, we found that it abuses the Windows Management Instrumentation (WMI) utility for lateral movement. Let’s analyze logs for anomalous use of WMI providers, especially outside of working hours or from non-privileged accounts.”
Thus, it can be said that IoCs can initiate threat hunting and a full incident investigation. Working with them allows you to launch many hypotheses and find things you would not have found by simply reviewing detections 🤔
#ioc #detect #tip
@ptescalator
More in Indicators & C2
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
- Hunting RATs by their own certificates 🕵️
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree:…






