417. Ransomware Gangs Abuse Microsoft Windows Recovery Agent
Hello everyone!
Today, we’ll take another look at the Inhibit System Recovery (T1490) technique, this time focusing on how threat actors use the Microsoft Windows Recovery Agent.
As you already know, attackers do not always limit themselves to deleting shadow copies. They may also disable other operating system recovery capabilities. In this case, the attackers also disabled the Windows Recovery Environment (WinRE). To do so, the Settra ransomware executed the following command:
reagentc /disable
Of course, this activity can be legitimate. Nevertheless, it is quite suitable for proactive threat hunting:
event_type: "processcreatewin"
AND
proc_file_path: "reagentc.exe"
AND
cmdline: "disable"
Once again, it is worth noting that although this was part of the ransomware’s functionality in this particular case, the same technique can also be used by attackers as part of their preparations for encrypting an IT environment.
See you soon!

Comments
Post a Comment