153. Here's How Threat Actors Hinder Forensic Recovery

Hello everyone!

I'm sure you love forensics. I do! But threat actors... I dont think so. That's why they have various techniques in their arsenal to hinder forensic analysis and recovery!

For example, CyberLock. The adversary abused cipher.exe to erase free space and harden forensic recovery:

Start-Process cipher.exe -ArgumentList "/w:C:\" -WindowStyle Hidden

Of course, hunting for ransomware isn't a good idea, but we can face this procedure in other cases as well. For example, to wipe free space after deleting the toolset. So it may also be a good candidate for a hunting query:

event_type: "processcreatewin"

AND

proc_file_originalfilename: "cipher.exe"

See you tomorrow!

Comments

Popular posts from this blog

033. Free Google Threat Intelligence Course

082. Huniting for Malicious Browser Extensions

001. The Zeltser Challenge