Analytics Story: BlueHammer

Description

Detect activity associated with BlueHammer exploit. Released by Nightmare-Eclipse on GitHub alongside RedSun and UnDefend, it is part of a set of attacks that abuse Windows Defender to disrupt the system or elevate privileges.

Why it matters

BlueHammer is a Windows local privilege escalation (LPE) exploit that allows a threat actor who already has a foothold on a system to elevate from a low-privileged user account to full SYSTEM-level control. It abuses the Windows Defender update process via Volume Shadow Copy, using Cloud Files callbacks and oplocks to pause Defender at a critical moment — exposing the SAM, SYSTEM, and SECURITY registry hives. This enables an attacker to read the SAM database, decrypt NTLM password hashes, take over a local administrator account, and spawn a SYSTEM-level shell, while restoring the original hash to avoid detection.

Detections

Name ▲▼ Technique ▲▼ Type ▲▼
Windows Admin Password Changed by Non-Admin Exploitation for Privilege Escalation, Windows Service TTP
Windows MsMpEng Writing to System32 Exploitation for Privilege Escalation, Windows Service TTP
Windows Cloud Files Filter Loaded by Uncommon Process Windows Service Anomaly
Windows Suspicious Defender Engine or Signature Files Created Exploitation for Privilege Escalation Anomaly
Windows Suspicious Defender Update Activity in INetCache Exploitation for Privilege Escalation, Ingress Tool Transfer Anomaly
Windows Suspicious Burst of Password Changes Exploitation for Privilege Escalation TTP
Windows Non-System Process Querying Definition Update Exploitation for Privilege Escalation, Web Protocols Anomaly

Data Sources

Name ▲▼ Platform ▲▼ Sourcetype ▲▼ Source ▲▼
Windows Event Log Security 4723 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Sysmon EventID 11 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 15 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 7 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 23 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Windows Event Log Security 4724 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Sysmon EventID 22 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

References


Source: GitHub | Version: 1