Analytics Story: RedSun

Description

Detect activity associated with RedSun exploit. Released by Nightmare-Eclipse on GitHub alongside BlueHammer and UnDefend, it is part of a set of attacks that abuse Windows Defender to disrupt the system or elevate privileges.

Why it matters

RedSun is a zero-day LPE vulnerability in Microsoft Defender that allows a low-privileged user to gain full NT AUTHORITY\SYSTEM access without any kernel exploit or administrator interaction. It abuses a logic flaw in how Defender handles cloud-tagged files during remediation — when Defender detects a malicious file carrying a cloud tag, it attempts to restore the file to its original location rather than quarantine it, running that restore operation with full SYSTEM privileges without validating whether the target path has been tampered with. An attacker redirects that write via an NTFS junction into C:\Windows\System32, dropping an attacker-controlled binary and executing it as SYSTEM through a COM service invocation — never touching credentials.

Detections

Name ▲▼ Technique ▲▼ Type ▲▼
Windows VSSVC Process Accessing Defender Engine Exploitation for Privilege Escalation TTP
Windows Suspicious Child Process of TieringEngineService.exe Exploitation for Privilege Escalation TTP
Windows Cloud Files Filter Loaded by Uncommon Process Windows Service Anomaly
Windows Cloud Files Filter Log Created by Non-System Process Exploitation for Privilege Escalation TTP
Windows MsMpEng Writing to System32 Exploitation for Privilege Escalation, Windows Service TTP
Windows Non-System Process Querying Definition Update Exploitation for Privilege Escalation, Web Protocols Anomaly

Data Sources

Name ▲▼ Platform ▲▼ Sourcetype ▲▼ Source ▲▼
Sysmon EventID 10 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
CrowdStrike ProcessRollup2 Other crowdstrike:events:sensor crowdstrike
Sysmon EventID 1 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Windows Event Log Security 4688 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Sysmon EventID 7 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 11 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 15 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 22 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

References


Source: GitHub | Version: 1