| ID | Technique | Tactic |
|---|---|---|
| T1068 | Exploitation for Privilege Escalation | Privilege Escalation |
Detection: Windows Defender Intermediary Artifact Was Observed
Description
The following analytic detects creation and removal of intermediary remediation artifacts of Windows Defender, during exploitation of ShieldCrash attacks. Exploit abuses the race condition between file validation and its remediation performed by Windows Defender. In between these steps, ShieldCrash changes the symbolic link to redirect the remediation process to a staging directory controlled by the attacker. This detection aims to detect creation of defender artifact, its alternate data stream, and their subsequent removal.
Search
1`sysmon`
2EventID IN (11, 15, 23)
3process_name IN (
4 "System",
5 "msmpeng.exe"
6)
7user=SYSTEM
8NOT TargetFilename IN (
9 "C:\\Windows\\Temp\\*",
10 "*:Zone.Identifier",
11 "*:SmartScreen"
12)
13
14
15| regex TargetFilename!="(?i)\.\w{1,10}$"
16
17
18| stats count values(EventID) as EventID
19 values(TargetFilename) as TargetFilename
20 dc(EventID) as dc_EventID
21 dc(TargetFilename) as dc_TargetFilename
22 min(_time) as firstTime
23 max(_time) as lastTime
24
25 by dest process_id process_name user
26
27
28| search dc_TargetFilename>1 dc_EventID>1
29
30
31| `security_content_ctime(firstTime)`
32
33| `security_content_ctime(lastTime)`
34
35| `windows_defender_intermediary_artifact_was_observed_filter`
Data Source
| Name | Platform | Sourcetype | Source |
|---|---|---|---|
| Sysmon EventID 11 | 'XmlWinEventLog' |
'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational' |
|
| Sysmon EventID 15 | 'XmlWinEventLog' |
'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational' |
|
| Sysmon EventID 23 | 'XmlWinEventLog' |
'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational' |
Macros Used
| Name | Value |
|---|---|
| security_content_ctime | convert timeformat="%Y-%m-%dT%H:%M:%S" ctime($field$) |
| windows_defender_intermediary_artifact_was_observed_filter | search * |
windows_defender_intermediary_artifact_was_observed_filter is an empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
Annotations
Default Configuration
This detection is configured by default in Splunk Enterprise Security to run with the following settings:
| Setting | Value |
|---|---|
| Disabled | true |
| Cron Schedule | 0 * * * * |
| Earliest Time | -70m@m |
| Latest Time | -10m@m |
| Schedule Window | auto |
| Creates Finding (Notable) | No |
| Creates Intermediate Finding (Risk Event) | Yes |
Implementation
To successfully implement this search, you need to be ingesting file creation, file stream creation and file deletion events from your endpoints using Sysmon. These logs must be processed using the latest Sysmon Technical Add-on (https://splunkbase.splunk.com/app/5709). Make sure to update Sysmon configuration to include directories you would like to monitor for these kinds of events.
Known False Positives
Remediation of various container files, such as archives, might also lead to creation various defender artifacts SmartScreen interferes with the remediation process, potentially causing additional defender artifacts to be created.
Associated Analytic Story
Intermediate Findings
| Message | Entity Field | Entity Type | Risk Score |
|---|---|---|---|
| Intermediary artifacts [$TargetFilename$] were observed by [$process_name$] during Defender Remediation process on [$dest$] | dest | system | 20 |
Threat Objects
| Field | Type |
|---|---|
| TargetFilename | file_path |
References
-
https://www.cyderes.com/howler-cell/rogueplanet-windows-zero-day
-
https://www.cyderes.com/howler-cell/shieldcrash-microsoft-zero-day?hs_amp=true
-
https://socradar.io/blog/shieldcrash-poc-microsoft-defender-fix-bypass/
Detection Testing
| Test Type | Status | Dataset | Source | Sourcetype |
|---|---|---|---|---|
| Validation | ✅ Passing | N/A | N/A | N/A |
| Unit | ✅ Passing | Dataset | XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
XmlWinEventLog |
| Integration | ✅ Passing | Dataset | XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
XmlWinEventLog |
Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI.
Alternatively you can replay a dataset into a Splunk Attack Range
Source: GitHub |
Version: 1