Skip to content

New Approach on Handling Renamed Binaries - #4283

Open
onurmerdogan wants to merge 4 commits into
developfrom
renamed_binary_modifications
Open

onurmerdogan wants to merge 4 commits into
developfrom
renamed_binary_modifications

Conversation

@onurmerdogan

Copy link
Copy Markdown
Contributor

Details

Currently we are handling renamed binary scenarios using multiple detections, below is the list,

  • Detect mshta renamed
  • Detect Renamed PSExec
  • Suspicious MSBuild Rename
  • Windows Regsvr32 Renamed Binary
  • Windows Renamed Powershell Execution
  • Windows LOLBAS Executed As Renamed File
  • Detect Renamed RClone
  • Detect HTML Help Renamed
  • Detect Renamed WinRAR
  • Detect Renamed 7-Zip
  • Suspicious microsoft workflow compiler rename

This approach makes it harder to maintain them going forward. During runtime, they are all executed separately, which is not efficient. I suggest 3 main categories of renamed binaries, in order to improve maintenance and runtime going forward,

  • Renamed LOLBAS Binaries
  • Renamed Command Interpreters
  • Renamed Popular 3rd Party Software

Each category will have a single detection(Python being an exception due to complex regex that it requires) abstracted by a lookup file where we can easily update and improve for future enhancements.

This PR retires almost all previous renaming detections, while suggesting replacements, together with their corresponding lookup files.

@nasbench nasbench left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Left a couple of extra suggestions to enhance the experience and accuracy.

As discussed, we should reach out to SCE for the error in CI.

be an indicator that an adversary is attempting to evade defenses or execute malicious code.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

4688 does not provide an OFN field. So let's remove it from all detections.

Comment on lines +53 to +56
references:
- https://attack.mitre.org/techniques/T1036/
- https://attack.mitre.org/techniques/T1036/003/
- https://attack.mitre.org/techniques/T1059/

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we could other public refs that are not mitre. An additional 1 or 2 should suffice.
This applies to the others as well.

@@ -0,0 +1,43 @@
original_file_name,software_name

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The other lookups use description instead of software name (which is redundant a little bit). I suggest we switch to description.

Comment on lines +27 to +31
AND NOT [
| inputlookup renamed_popular_3rd_party_binaries.csv
| rename original_file_name as Processes.process_name
| table Processes.process_name
]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

while this would work in 90% if the cases, OFN is not always == process_name. The very famous example is pwsh.exe (for PowerShell 7) has an OFN of pwsh.dll.

For this i suggest we spend more time collecting the actual process names and OFN's in dedicated columns.

If you get started and I can help fill any gaps.

entities:
- field: dest
type: system
score: 30

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The current convention starts new anomaly rules with a score of 20. So please apply that to all.

- field: dest
type: system
score: 30
message: LOLBAS utility [$original_file_name$] was renamed as [$process_name$] and later executed on [$dest$]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the message should also include the process_path for more clarity, since that's usually also interesting to know.

@nasbench nasbench left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Additional suggestions to add local=t so that this lookup will run locally (since we do not copy lookups to distributed installations).

| eval original_file_name=lower(original_file_name)
| where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe",""))
| where NOT match(process_name, "(?i)".original_file_name)
| lookup renamed_windows_command_interpreter_binaries original_file_name OUTPUT description

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
| lookup renamed_windows_command_interpreter_binaries original_file_name OUTPUT description
| lookup local=t renamed_windows_command_interpreter_binaries original_file_name OUTPUT description

| eval original_file_name=lower(original_file_name)
| where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe",""))
| where NOT match(process_name, "(?i)".original_file_name)
| lookup renamed_lolbas_binaries original_file_name OUTPUT description

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
| lookup renamed_lolbas_binaries original_file_name OUTPUT description
| lookup local=t renamed_lolbas_binaries original_file_name OUTPUT description

| eval original_file_name=lower(original_file_name)
| where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe",""))
| where NOT match(process_name, "(?i)".original_file_name)
| lookup renamed_popular_3rd_party_binaries original_file_name OUTPUT software_name

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
| lookup renamed_popular_3rd_party_binaries original_file_name OUTPUT software_name
| lookup local=t renamed_popular_3rd_party_binaries original_file_name OUTPUT software_name

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants