This follows Will Any of This Fire?. That post introduced a method. Break a threat report into behaviors, then move from technique tag to predicate leaf to structural pivot. This post applies the method to six threat reports. It also covers kind:, with:, field:, correlation:, and excludes:.
Many thanks to the analysts at The DFIR Report for their work.
The field operator earns its keep
Atera RMM was installed as a service during the RansomHub intrusion. The field: operator anchors a value to a predicate field. This query searches for Atera as a ServiceName predicate using a contains match.field:ServiceName value:atera kind:contains3 results |
Identifies the use of Cloudflare Tunnel (cloudflared) to expose a local service or create an outbound tunnel. Adversaries may abuse quick tunnels (e.g. tunnel --url http://127.0.0.1:80) or named tunnels to proxy C2 traffic or exfiltrate data through Cloudflare's edge while evading direct connection blocking.
Detects creation of an ad-hoc Cloudflare Quick Tunnel, which can be used to tunnel local services such as HTTP, RDP, SSH and SMB. The free TryCloudflare Quick Tunnel will generate a random subdomain on trycloudflare[.]com, following a call to api[.]trycloudflare[.]com. The tool has been observed in use by threat groups including Akira ransomware.
T1071.001 Application Layer Protocol: Web ProtocolsT1102 Web ServiceT1567.002 Exfiltration Over Web Service: Exfiltration to Cloud StorageT1567.003 Exfiltration Over Web Service: Exfiltration to Text Storage SitesT1567.004 Exfiltration Over Web Service: Exfiltration Over Webhook
This rule monitors for the unusual occurrence of outbound network connections to suspicious webservice domains.
T1567 Exfiltration Over Web ServiceT1572 Protocol Tunneling
Detects network connections to Cloudflared tunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
Detects an executable, which is not an internet browser or known application, initiating network connections to legit popular websites, which were seen to be used as dead drop resolvers in previous attacks. In this context attackers leverage known websites such as "facebook", "youtube", etc. In order to pass through undetected.
T1187 Forced AuthenticationT1550 Use Alternate Authentication MaterialT1557.001 Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay
Detects potential relay attacks by identifying coercion attempts followed by authentication events using a target server's computer account, originating from a different host. This may indicate that an attacker has captured and relayed Kerberos authentication material for the server's computer account to execute code on behalf of the compromised system.
T1187 Forced AuthenticationT1557.001 Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay
Detects potential relay attacks by identifying coercion attempts followed by authentication events using a target server's computer account, originating from a different host. This may indicate that an attacker has captured and relayed the server's computer account hash to execute code on behalf of the compromised system.
This query detects instances where an attacker has gained the ability to execute code on an ADFS Server through SMB and Remote Service or Scheduled Task.
NetSync allows an attacker to take the NTLM hash of a Domain Controller (DC) machine account ("usually" identified by ending in "$") and using it to obtain the NTLM machine account hash of another machine account through impersonation (similar to, but different from, DCSync). Where DCSync can obtain user account passwords, NetSync is limited to machine accounts. The other main differentiator between DCSync and NetSync is that DCSync will make use of Microsoft's Directory Replication Service (DRS...
Detects scenarios where an attacker perform a password reset event. This does not require any knowledge of a user’s current password, but it does require to have the "Reset Password" right. Correlate the event ID 4724, 4624 and 5145 using the "SubjectLogonId" field to identify the source of the reset.
Threat actors may scan for hosts with SMB ports exposed to the internet and attempt to access services. This rule detects external attempts to access SMB shares (Event IDs 5140 or 5145) following network logons (Event ID 4624, Logon Type 3) within a one minute period correlated by host and user, which may indicate a threat actor's initial access attempt via SMB.
Detects suspicious local connections via a named pipe to the AD FS configuration database (Windows Internal Database). Used to access information such as the AD FS configuration settings which contains sensitive information used to sign SAML tokens.
Identifies multiple logon failures followed by a successful one from the same source address. Adversaries will often brute force login attempts across multiple users with a common or known password, in an attempt to gain access to accounts.
T1187 Forced AuthenticationT1550 Use Alternate Authentication MaterialT1557.001 Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay
Detects potential relay attacks by identifying coercion attempts followed by authentication events using a target server's computer account, originating from a different host. This may indicate that an attacker has captured and relayed Kerberos authentication material for the server's computer account to execute code on behalf of the compromised system.
T1187 Forced AuthenticationT1557.001 Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay
Detects potential relay attacks by identifying coercion attempts followed by authentication events using a target server's computer account, originating from a different host. This may indicate that an attacker has captured and relayed the server's computer account hash to execute code on behalf of the compromised system.
Identifies accounts who have failed to logon to the domain multiple times in a row, followed by a successful authentication within a short time frame. Multiple failed attempts followed by a success can be an indication of a brute force attempt or possible mis-configuration of a service account within an environment. The lookback is set to 2h and the authentication window and threshold are set to 1h and 5, meaning we need to see a minimum of 5 failures followed by a success for an account within ...
18 stagessequencewindow: 10mevents: 4624, 4625
Privilege escalation, credential access, C2
Lunar Spider performed a UAC bypass through a registry hijack of HKCU\Software\Classes\ms-settings\shell\open\command. The uses:TargetObject clause limits results to rules that inspect the registry path field.value:ms-settings uses:TargetObject6 results |
T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
Identifies attempts to bypass User Account Control (UAC) via ComputerDefaults execution hijack. Attackers bypass UAC to stealthily execute code with elevated permissions.
T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
Identifies User Account Control (UAC) bypass via fodhelper.exe execution hijack. Attackers bypass UAC to stealthily execute code with elevated permissions.
T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
This detection looks for the steps required to conduct a UAC bypass using Fodhelper.exe. By default this detection looks for the setting of the required registry keys and the invoking of the process within 1 hour - this can be tweaked as required.
T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
This detection looks for the steps required to conduct a UAC bypass using Fodhelper.exe. By default this detection looks for the setting of the required registry keys and the invoking of the process within 1 hour - this can be tweaked as required.
T1546.001 Event Triggered Execution: Change Default File AssociationT1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
Detects the shell open key manipulation (exefile and ms-settings) used for persistence and the pattern of UAC Bypass using fodhelper.exe, computerdefaults.exe, slui.exe via registry keys (e.g. UACMe 33 or 62)
T1003.001 OS Credential Dumping: LSASS MemoryT1003.003 OS Credential Dumping: NTDS
Identifies the execution of known Windows utilities often abused to dump LSASS memory or the Active Directory database (NTDS.dit) in preparation for credential access.
T1003.001 OS Credential Dumping: LSASS MemoryT1036.003 Masquerading: Rename Legitimate UtilitiesT1218.011 System Binary Proxy Execution: Rundll32
Identifies suspicious renamed COMSVCS.DLL Image Load, which exports the MiniDump function that can be used to dump a process memory. This may indicate an attempt to dump LSASS memory while bypassing command-line based detection in preparation for credential access.
T1003.001 OS Credential Dumping: LSASS MemoryT1003.003 OS Credential Dumping: NTDST1218.011 System Binary Proxy Execution: Rundll32
Identifies the execution of known Windows utilities often abused to dump LSASS memory or the Active Directory database (NTDS.dit) in preparation for credential access.
T1036.001 Masquerading: Invalid Code SignatureT1036.005 Masquerading: Match Legitimate Resource Name or LocationT1553.002 Subvert Trust Controls: Code SigningT1554 Compromise Host Software BinaryT1574.001 Hijack Execution Flow: DLL
Identifies suspicious instances of default system32 DLLs either unsigned or signed with non-MS certificates. This can potentially indicate the attempt to masquerade as system DLLs, perform DLL Search Order Hijacking or backdoor and resign legitimate DLLs.
DNS queries for the Tor .onion TLD offer another example. It anchors a domain suffix to the DNS query field.field:QueryName value:.onion25 results, showing first 10 |