[ << ALL_FEED ]

While investigating the incident, we discovered a useful artifact smb_context

More in General

💻 While investigating an incident, we discovered a useful artifact, smb_context

C:\Windows\SysWOW64\smb_context.log — the SMB event log from a well-known antivirus vendor.

We have not yet fully investigated how it works, but we found that by analyzing this log, it is possible to detect command execution, in particular using the smbexec, utility, as well as file access on disk.

The log may contain the following events:


PDMSmbFileAccessed
PDMSmbCreateFile
PDMSmbRenameFile

Example:


<BeginStream>
PDMSmbFileAccessed("$windir\__1715675753.48",00000011000000000010010100100000,1399528814);
PDMSmbFileAccessed("$system32\cmpspy.dll",00001011110000000010001100100001,1399106043);
PDMSmbFileAccessed("$system32\reg.bat",00001011110000000010001100100001,1399106043);
<EndStream>

<BeginStream>
PDMSmbFileAccessed("$windir\psexesvc.exe",00001010100000000010001100100001,405741904);
<EndStream>

#tool #detect #hunt
@ptescalator

More from global_author

More from global_author

More in General