Detection rules › Splunk
Service Stop Commands (PowerShell)
Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Defense Impairment | |
| Impact |
References
Telemetry coverage
| Provider | Record / event type |
|---|---|
| PowerShell | Event ID 4104: Creating Scriptblock text (MessageNumber of MessageTotal). |
Rule body
id: '5367.5471'
title: Service Stop Commands
description: 'Adversaries may stop or disable services on a system to render those
services unavailable to legitimate users. Stopping critical services can inhibit
or stop response to an incident or aid in the adversary''s overall objectives to
cause damage to the environment. Threat Actor Association: APT29/Nobelium/Cozy Bear,
FIN6, Kimsuky, Lapsus$, Lazarus, TA2541, Traveling Spider - Software Association:
BlackByte, Blackcat/ALPHV, Black Basta, Conti, Cring, Cuba, GhostShell, Lockbit,
Nefilim, Prometheus / Spook, Ryuk, TeamTNT, WatchDog, WhisperGate, XingLocker --
Atomics T1489 #Test1 Atomics T1489 #Test2 Atomics T1489 #Test3 -- #TrendingThreat
#Russia #Ukraine'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_powershell` signature_id=4104 AND ((TERM(sc.exe)
OR TERM(sc) OR TERM(net) OR TERM(net.exe) ) AND TERM(stop) AND (TERM(ShellHWDetection)
OR TERM(AVPSUS) OR TERM(McAfeeDLPAgentService) OR TERM(mfewc) OR TERM(eventlog)
OR (TERM(BMR) AND TERM(SERVICE))) OR ( TERM(taskkill) AND ( TERM(/IM) OR TERM(/PID)
OR TERM(/T) ) AND TERM(/F)) OR ((TERM(sc.exe) OR TERM(sc)) AND TERM(CONFIG) AND
TERM(START=) AND TERM(DISABLED))) | rex field=process mode=sed max_match=0 "s/(?mi)^(Path.+)|^(ScriptBlock
ID.+)|^(Creating Scriptblock.+)//g"| rex field=process mode=sed "s/([\n\r]+)|(\s\s+)//g"|
table _time, host, user event_id, parent_process, parent_process_id, parent_process_name,
parent_process_path, process, process_id, process_name, process_path, signature_id,
user_id | bin span=1s | stats values(*) as * by _time, host '
techniques:
- defense-evasion:impair defenses:disable or modify tools
- impact:service stop
technique_id:
- T1562.001
- T1489
data_category:
- PowerShell logs
- Process command-line parameters
references:
- https://www.mcafee.com/blogs/other-blogs/mcafee-labs/lockergoga-ransomware-family-used-in-targeted-attacks/
- https://kcm.trellix.com/resources/sites/MCAFEE/content/live/CORP_KNOWLEDGEBASE/91000/KB91373/en_US/McAfee%20Labs%20Threat%20Advisory%20-%20LockerGoga.pdf
Stages and Predicates
Stage 1: search
`get_endpoint_data` `get_endpoint_data_powershell` signature_id=4104 AND ((TERM(sc.exe) OR TERM(sc) OR TERM(net) OR TERM(net.exe) ) AND TERM(stop) AND (TERM(ShellHWDetection) OR TERM(AVPSUS) OR TERM(McAfeeDLPAgentService) OR TERM(mfewc) OR TERM(eventlog) OR (TERM(BMR) AND TERM(SERVICE))) OR ( TERM(taskkill) AND ( TERM(/IM) OR TERM(/PID) OR TERM(/T) ) AND TERM(/F)) OR ((TERM(sc.exe) OR TERM(sc)) AND TERM(CONFIG) AND TERM(START=) AND TERM(DISABLED)))
Stage 2: rex
| rex field=process mode=sed max_match=0 "s/(?mi)^(Path.+)|^(ScriptBlock ID.+)|^(Creating Scriptblock.+)//g"
Stage 3: rex
| rex field=process mode=sed "s/([\n\r]+)|(\s\s+)//g"
Stage 4: table
| table _time, host, user event_id, parent_process, parent_process_id, parent_process_name, parent_process_path, process, process_id, process_name, process_path, signature_id, user_id
Stage 5: bucket
| bin span=1s
Stage 6: stats
| stats values(*) as * by _time, host
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
signature_id | eq |
| field:"signature_id" kind:eq value:"4104" |
Search terms
These SPL tokens match against raw event text.
| Stage | Term |
|---|---|
| 1 | sc.exe |
| 1 | sc |
| 1 | net |
| 1 | net.exe |
| 1 | stop |
| 1 | ShellHWDetection |
| 1 | AVPSUS |
| 1 | McAfeeDLPAgentService |
| 1 | mfewc |
| 1 | eventlog |
| 1 | BMR |
| 1 | SERVICE |
| 1 | taskkill |
| 1 | "/IM" |
| 1 | "/PID" |
| 1 | "/T" |
| 1 | "/F" |
| 1 | sc.exe |
| 1 | sc |
| 1 | CONFIG |
| 1 | "START=" |
| 1 | DISABLED |