Analytics Story: Windows Persistence Techniques
Description
Monitor for activities and techniques associated with maintaining persistence on a Windows system--a sign that an adversary may have compromised your environment.
Why it matters
Maintaining persistence is one of the first steps taken by attackers after the initial compromise. Attackers leverage various custom and built-in tools to ensure survivability and persistent access within a compromised enterprise. This Analytic Story provides searches to help you identify various behaviors used by attackers to maintain persistent access to a Windows environment.
Detections
Data Sources
| Name | Platform | Sourcetype | Source |
|---|---|---|---|
| Windows Event Log Security 4742 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Windows Event Log Security 4738 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| CrowdStrike ProcessRollup2 | Other | crowdstrike:events:sensor |
crowdstrike |
| Sysmon EventID 1 | XmlWinEventLog |
XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
|
| Windows Event Log Security 4688 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Sysmon EventID 13 | XmlWinEventLog |
XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
|
| Windows Event Log Security 4698 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Windows Event Log TaskScheduler 201 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Windows Event Log TaskScheduler 200 | wineventlog |
WinEventLog:Microsoft-Windows-TaskScheduler/Operational |
|
| Sysmon EventID 11 | XmlWinEventLog |
XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
|
| Windows Event Log Security 5145 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Windows Event Log Application 3000 | XmlWinEventLog |
XmlWinEventLog:Application |
|
| Windows Event Log Security 4702 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Windows Event Log Security 4700 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Sysmon EventID 14 | XmlWinEventLog |
XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
|
| Sysmon EventID 12 | XmlWinEventLog |
XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
References
- https://www.youtube.com/watch?v=dq2Hv7J9fvk
- http://resources.infosecinstitute.com/common-malware-persistence-mechanisms/
- https://www.fireeye.com/blog/threat-research/2010/07/malware-persistence-windows-registry.html
- https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html
- http://www.fuzzysecurity.com/tutorials/19.html
Source: GitHub | Version: 3