153. Here's How Threat Actors Hinder Forensic Recovery
Hello everyone!
I'm sure you love forensics. I do! But threat actors... I dont think so. That's why they have various techniques in their arsenal to hinder forensic analysis and recovery!
For example, CyberLock. The adversary abused cipher.exe to erase free space and harden forensic recovery:
Start-Process cipher.exe -ArgumentList "/w:C:\" -WindowStyle Hidden
Of course, hunting for ransomware isn't a good idea, but we can face this procedure in other cases as well. For example, to wipe free space after deleting the toolset. So it may also be a good candidate for a hunting query:
event_type: "processcreatewin"
AND
proc_file_originalfilename: "cipher.exe"
See you tomorrow!
Comments
Post a Comment