New Approach on Handling Renamed Binaries - #4283
onurmerdogan wants to merge 4 commits into
Conversation
nasbench
left a comment
There was a problem hiding this comment.
LGTM. Left a couple of extra suggestions to enhance the experience and accuracy.
As discussed, we should reach out to SCE for the error in CI.
| be an indicator that an adversary is attempting to evade defenses or execute malicious code. | ||
| data_source: | ||
| - Sysmon EventID 1 | ||
| - Windows Event Log Security 4688 |
There was a problem hiding this comment.
4688 does not provide an OFN field. So let's remove it from all detections.
| references: | ||
| - https://attack.mitre.org/techniques/T1036/ | ||
| - https://attack.mitre.org/techniques/T1036/003/ | ||
| - https://attack.mitre.org/techniques/T1059/ |
There was a problem hiding this comment.
Maybe we could other public refs that are not mitre. An additional 1 or 2 should suffice.
This applies to the others as well.
| @@ -0,0 +1,43 @@ | |||
| original_file_name,software_name | |||
There was a problem hiding this comment.
The other lookups use description instead of software name (which is redundant a little bit). I suggest we switch to description.
| AND NOT [ | ||
| | inputlookup renamed_popular_3rd_party_binaries.csv | ||
| | rename original_file_name as Processes.process_name | ||
| | table Processes.process_name | ||
| ] |
There was a problem hiding this comment.
while this would work in 90% if the cases, OFN is not always == process_name. The very famous example is pwsh.exe (for PowerShell 7) has an OFN of pwsh.dll.
For this i suggest we spend more time collecting the actual process names and OFN's in dedicated columns.
If you get started and I can help fill any gaps.
| entities: | ||
| - field: dest | ||
| type: system | ||
| score: 30 |
There was a problem hiding this comment.
The current convention starts new anomaly rules with a score of 20. So please apply that to all.
| - field: dest | ||
| type: system | ||
| score: 30 | ||
| message: LOLBAS utility [$original_file_name$] was renamed as [$process_name$] and later executed on [$dest$] |
There was a problem hiding this comment.
I think the message should also include the process_path for more clarity, since that's usually also interesting to know.
nasbench
left a comment
There was a problem hiding this comment.
Additional suggestions to add local=t so that this lookup will run locally (since we do not copy lookups to distributed installations).
| | eval original_file_name=lower(original_file_name) | ||
| | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) | ||
| | where NOT match(process_name, "(?i)".original_file_name) | ||
| | lookup renamed_windows_command_interpreter_binaries original_file_name OUTPUT description |
There was a problem hiding this comment.
| | lookup renamed_windows_command_interpreter_binaries original_file_name OUTPUT description | |
| | lookup local=t renamed_windows_command_interpreter_binaries original_file_name OUTPUT description |
| | eval original_file_name=lower(original_file_name) | ||
| | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) | ||
| | where NOT match(process_name, "(?i)".original_file_name) | ||
| | lookup renamed_lolbas_binaries original_file_name OUTPUT description |
There was a problem hiding this comment.
| | lookup renamed_lolbas_binaries original_file_name OUTPUT description | |
| | lookup local=t renamed_lolbas_binaries original_file_name OUTPUT description |
| | eval original_file_name=lower(original_file_name) | ||
| | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) | ||
| | where NOT match(process_name, "(?i)".original_file_name) | ||
| | lookup renamed_popular_3rd_party_binaries original_file_name OUTPUT software_name |
There was a problem hiding this comment.
| | lookup renamed_popular_3rd_party_binaries original_file_name OUTPUT software_name | |
| | lookup local=t renamed_popular_3rd_party_binaries original_file_name OUTPUT software_name |
Details
Currently we are handling renamed binary scenarios using multiple detections, below is the list,
This approach makes it harder to maintain them going forward. During runtime, they are all executed separately, which is not efficient. I suggest 3 main categories of renamed binaries, in order to improve maintenance and runtime going forward,
Each category will have a single detection(Python being an exception due to complex regex that it requires) abstracted by a lookup file where we can easily update and improve for future enhancements.
This PR retires almost all previous renaming detections, while suggesting replacements, together with their corresponding lookup files.