Analytics Story: Ransomware

Description

Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware--spikes in SMB traffic, suspicious wevtutil usage, the presence of common ransomware extensions, and system processes run from unexpected locations, and many others.

Why it matters

Ransomware is an ever-present risk to the enterprise, wherein an infected host encrypts business-critical data, holding it hostage until the victim pays the attacker a ransom. There are many types and varieties of ransomware that can affect an enterprise. Attackers can deploy ransomware to enterprises through spearphishing campaigns and driveby downloads, as well as through traditional remote service-based exploitation. In the case of the WannaCry campaign, there was self-propagating wormable functionality that was used to maximize infection. Fortunately, organizations can apply several techniques--such as those in this Analytic Story--to detect and or mitigate the effects of ransomware.

Detections

Name ▲▼ Technique ▲▼ Type ▲▼
Detect SharpHound Usage Local Groups, Domain Groups, Local Account, Domain Account, Domain Trust Discovery TTP
Recon AVProduct Through Pwh or WMI Gather Victim Host Information TTP
Windows Disable Windows Group Policy Features Through Registry Modify Registry Anomaly
Delete ShadowCopy With PowerShell Inhibit System Recovery TTP
Allow Network Discovery In Firewall Cloud Firewall TTP
Windows Event Log Cleared Clear Windows Event Logs TTP
ICACLS Grant Command File and Directory Permissions Modification Anomaly
Windows Scheduled Task with Suspicious Command Scheduled Task TTP
Windows Hide Notification Features Through Registry Modify Registry Anomaly
Allow File And Printing Sharing In Firewall Cloud Firewall TTP
WinEvent Scheduled Task Created to Spawn Shell Scheduled Task TTP
Revil Registry Entry Modify Registry TTP
Detect Remote Access Software Usage FileInfo Remote Access Tools Anomaly
Windows Disable Lock Workstation Feature Through Registry Modify Registry Anomaly
Disable AMSI Through Registry Disable or Modify Tools TTP
Cisco Secure Firewall - Remote Access Software Usage Traffic Remote Access Tools Anomaly
Windows DotNet Binary in Non Standard Path Rename Legitimate Utilities, InstallUtil TTP
Detect SharpHound File Modifications Local Groups, Domain Groups, Local Account, Domain Account, Domain Trust Discovery TTP
Windows Set Account Password Policy To Unlimited Via Net Service Stop Anomaly
Windows Event Logging Service Has Shutdown Clear Windows Event Logs Hunting
Detect Remote Access Software Usage File Remote Access Tools Anomaly
7zip CommandLine To SMB Share Path Archive via Utility Hunting
Linux EFI Bootloader File Deletion System Firmware, Bootkit TTP
Windows Disable Change Password Through Registry Modify Registry Anomaly
Clear Unallocated Sector Using Cipher App File Deletion TTP
Windows Disable Shutdown Button Through Registry Modify Registry Anomaly
Rundll32 LockWorkStation Rundll32 Anomaly
Conti Common Exec parameter User Execution TTP
Windows Registry Modification for Safe Mode Persistence Registry Run Keys / Startup Folder TTP
TOR Traffic Multi-hop Proxy TTP
Detect RClone Command-Line Usage Automated Exfiltration TTP
Msmpeng Application DLL Side Loading DLL TTP
Disable ETW Through Registry Disable or Modify Tools TTP
Detect Remote Access Software Usage Registry Remote Access Tools Anomaly
Detect Remote Access Software Usage Process Remote Access Tools Anomaly
Remote Process Instantiation via WMI Windows Management Instrumentation TTP
Uninstall App Using MsiExec Msiexec TTP
Prohibited Network Traffic Allowed Exfiltration Over Alternative Protocol TTP
Execute Javascript With Jscript COM CLSID Visual Basic TTP
Windows Raccine Scheduled Task Deletion Disable or Modify Tools TTP
Windows InstallUtil in Non Standard Path Rename Legitimate Utilities, InstallUtil TTP
USN Journal Deletion Indicator Removal TTP
BCDEdit Failure Recovery Modification Inhibit System Recovery TTP
Suspicious wevtutil Usage Clear Windows Event Logs TTP
Detect SharpHound Command-Line Arguments Local Groups, Domain Groups, Local Account, Domain Account, Domain Trust Discovery TTP
MS Exchange Mailbox Replication service writing Active Server Pages External Remote Services, Exploit Public-Facing Application, Web Shell TTP
Windows NirSoft AdvancedRun Tool TTP
Detect Renamed RClone Automated Exfiltration Hunting
Windows Remote Image Load Command and Scripting Interpreter, Exploitation for Privilege Escalation, Shared Modules, Exploitation for Client Execution Anomaly
Revil Common Exec Parameter User Execution TTP
WBAdmin Delete System Backups Inhibit System Recovery TTP
Schtasks used for forcing a reboot Scheduled Task TTP
WinEvent Scheduled Task Created Within Public Path Scheduled Task TTP
Windows DiskCryptor Usage Data Encrypted for Impact Hunting
Detect Remote Access Software Usage Traffic Remote Access Tools Anomaly
Windows Security And Backup Services Stop Inhibit System Recovery TTP
Powershell Disable Security Monitoring Disable or Modify Tools TTP
Disable Logs Using WevtUtil Clear Windows Event Logs TTP
UAC Bypass With Colorui COM Object CMSTP TTP
Suspicious Scheduled Task from Public Directory Scheduled Task Anomaly
Windows Excessive Service Stop Attempt Service Stop TTP
Windows Disable LogOff Button Through Registry Modify Registry Anomaly
Windows Disable Memory Crash Dump Data Destruction TTP
CMLUA Or CMSTPLUA UAC Bypass CMSTP TTP
Detect Remote Access Software Usage URL Remote Access Tools Anomaly
Common Ransomware Extensions Data Destruction TTP
Registry Keys Used For Persistence Registry Run Keys / Startup Folder TTP
Windows Eventlog Cleared Via Wevtutil Clear Windows Event Logs Anomaly
Excessive Usage Of SC Service Utility Service Execution Anomaly
Windows Process Execution in Temp Dir Match Legitimate Resource Name or Location, Create or Modify System Process Anomaly
Wbemprox COM Object Execution CMSTP TTP
Detect Remote Access Software Usage DNS Remote Access Tools Anomaly
Powershell Enable SMB1Protocol Feature Indicator Removal from Tools TTP
Unusually Long Command Line None Anomaly
Deleting Shadow Copies Inhibit System Recovery TTP
Recursive Delete of Directory In Batch CMD File Deletion TTP
Windows Excessive Usage Of Net App Account Access Removal Anomaly
Allow Operation with Consent Admin Abuse Elevation Control Mechanism TTP
Windows RMM Named Pipe SMB/Windows Admin Shares, Process Injection, Inter-Process Communication Anomaly
Windows Scheduled Task with Suspicious Name Scheduled Task TTP
Prevent Automatic Repair Mode using Bcdedit Inhibit System Recovery TTP
Disable Windows Behavior Monitoring Disable or Modify Tools TTP
Modification Of Wallpaper Defacement TTP
Spike in File Writes None Anomaly
Fsutil Zeroing File Indicator Removal TTP
Common Ransomware Notes Data Destruction Hunting
Permission Modification using Takeown App File and Directory Permissions Modification Anomaly
SMB Traffic Spike SMB/Windows Admin Shares Anomaly
Windows .Key File Creation in Root Directory Data Encrypted for Impact Anomaly
Powershell Execute COM Object PowerShell, Component Object Model Hijacking TTP
System Processes Run From Unexpected Locations Rename Legitimate Utilities Anomaly

Data Sources

Name ▲▼ Platform ▲▼ Sourcetype ▲▼ Source ▲▼
CrowdStrike ProcessRollup2 Other crowdstrike:events:sensor crowdstrike
Sysmon EventID 1 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Windows Event Log Security 4688 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Powershell Script Block Logging 4104 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
Sysmon EventID 13 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Windows Event Log Security 1102 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Windows Event Log System 104 Windows icon Windows XmlWinEventLog XmlWinEventLog:System
Windows Event Log Security 4700 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Windows Event Log Security 4698 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Windows Event Log Security 4702 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Sysmon EventID 12 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Cisco Secure Firewall Threat Defense Connection Event Other cisco:sfw:estreamer not_applicable
Sysmon EventID 11 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Windows Event Log Security 1100 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Sysmon for Linux EventID 11 Linux icon Linux sysmon:linux Syslog:Linux-Sysmon/Operational
Palo Alto Network Traffic Network icon Network pan:traffic not_applicable
Cisco Network Visibility Module Flow Data Network icon Network cisco:nvm:flowdata:v2 not_applicable
Sysmon EventID 7 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Windows Event Log System 7036 Windows icon Windows XmlWinEventLog XmlWinEventLog:System
Palo Alto Network Threat Network icon Network pan:threat not_applicable
Sysmon EventID 22 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 18 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 17 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

References


Source: GitHub | Version: 2