Posts

Showing posts with the label TamperedChef

325. Can We Use Discovery Techniques for Hunting?

Image
Hello everyone! A very typical behaviour marker for many malware families - executing system discovery commands. And, of course, we can use it for threat hunting! Let's look at  TamperedChef  campaign. The adversary performs registry query to look for the victim's machine ID: reg.exe QUERY "HKLM\Software\Microsoft\Cryptography" /v MachineGuid If we use it for hunting, we'll have to filter lots and lots of false positives, but still it may be a good hypothesis - just focus on parent processes. In our example - it's quite suspicious as it's node.exe , so we can use it to build a query: event_type: "processcreatewin" AND proc_p_file_path: "node.exe" AND proc_file_path: "reg.exe" AND cmdline: "machineguid" See you tomorrow!

245. That's How TamperedChef Queries the System for Security Products

Image
Hello everyone! It's very important for an adversary to collect information about security software available on the compromised system. Let's look at another real-world example demonstrating how threat actors leverage  Security Software Discovery (T1518.001) and Query Registry (T1012) . So, according to this report ,  TamperedChef abused reg.exe (yes, again) to query system registry on order to obtain information about security software installed, for example: reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Bitdefender" /v "UninstallString" We can use security software names to build our detection: event_type: "processcreatewin" AND proc_file_path: "reg.exe" AND cmdline: ("query" AND ("bitdefender" OR "g data antivirus" OR "checkpoint" OR "kasperskylabsetup" OR "fortinet" OR "zillya antivirus")) See you tomorrow!