Posts

Showing posts with the label discovery

362. Ransomware Gangs Use This Tool for Discovery

Image
Hello everyone! Today we'll talk about how ransomware gangs abuse legitimate software for  File and Directory Discovery (T1083) . And our example for today's post - NightSpire . Anong other tools, the gang leveraged Everything - a legitimate tool that enables an adversary to index files and get a deeper understanding of data available on the compromised system. So, this tool, especially if it's not widely used internaly, may be a good target for hunting: event_type: "processcreatewin" AND proc_file_originalfilename: "everything.exe" See you tomorrow!

330. Adversaries Use Windows Event Logs for Discovery

Image
Hello everyone! We often use Windows Event Logs during our incident response engagements, but adversaries may also use it, for example, for discovery. Let's dig into this report . The adversary leveraged SharpADUserIP, which enables them to collect information about user names and their IP addresses from Security log, as we as the following PowerShell command to extract similar information from Microsoft-Windows-TerminalServices-LocalSessionManager/Operational: powershell -Command Get-WinEvent -LogName 'Microsoft-Windows-TerminalServices-LocalSessionManager/Operational' | Where-Object {$_.Id -eq 21} | ForEach-Object { $eventXml = [xml]$_.ToXml(); $username = $eventXml.Event.UserData.EventXML.User; $ipAddress = $eventXml.Event.UserData.EventXML.Address; $loginTime = $_.TimeCreated; if ($username -and $ipAddress -and $loginTime) { Write-Output ('User: ' + $username + ' IP: ' + $ipAddress + ' Login Time: ' + $loginTime) }} So, we can hunt for suspicious...

313. Here's How Real Adversaries Abuse PowerShell for Discovery

Image
Hello everyone! Today we'll look at another example of PowerShell abuse. And this time we'll talk about the Discovery tactic. So, let's look into the report on Gootloader . There're multiple interesting examples of PowerShell abuse. The adversary uses it to search for accounts with SPNs: powershell.exe  -command "$search = New-Object DirectoryServices.DirectorySearcher([ADSI]''); $search.Filter = '(&(servicePrincipalName=*)(objectCategory=user))'; $results = $search.FindAll(); foreach ($result in $results) { $u = $result.GetDirectoryEntry(); Write-Host $u.name, $u.samaccountname; foreach ($s in $u.servicePrincipalName) { Write-Host $s; } Write-Host '---'; }" Finds computers where the current user has admin rights: powershell.exe  -ExecutionPolicy bypass -Command "$UBcPGBjR99={param($vars);$nZzkzLTK99=$vars.computer;$Error.clear();Get-WmiObject -Class Win32_OperatingSystem -ComputerName $nZzkzLTK99 -ErrorAction SilentlyContinue;...

258. That's How Adversaries Abuse WMI for Software Discovery

Image
Hello everyone! Let's talk about discovery one more time as this is one of the best tactics to catch the bad guys before it's too late. This time we'll look at  Software Discovery (T1518) . So, according to this report , the adversary leveraged WMI for browser-related process enumeration: C:\windows\system32\cmd.exe /d /s /c "powershell.exe "Get-WmiObject Win32_Process | Where-Object { $_.Name -eq 'chrome.exe' }"" C:\windows\system32\cmd.exe /d /s /c "powershell.exe "Get-WmiObject Win32_Process | Where-Object { $_.Name -eq 'msedge.exe' }"" Yes, it's another great target for your threat hunting mission: event_type: "processcreatewin" AND cmdline: ("Get-WmiObject" AND "Win32_Process") AND cmdline: ("chrome.exe" OR "msedge.exe") See you tomorrow!