Analytics Story: Windows Persistence Techniques
Description
Monitor for activities and techniques associated with maintaining persistence on a Windows system--a sign that an adversary may have compromised your environment.
Why it matters
Maintaining persistence is one of the first steps taken by attackers after the initial compromise. Attackers leverage various custom and built-in tools to ensure survivability and persistent access within a compromised enterprise. This Analytic Story provides searches to help you identify various behaviors used by attackers to maintain persistent access to a Windows environment.
Detections
Data Sources
| Name | Platform | Sourcetype | Source |
|---|---|---|---|
| Sysmon EventID 13 | XmlWinEventLog |
XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
|
| Sysmon EventID 11 | XmlWinEventLog |
XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
|
| Windows Event Log Security 4700 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Windows Event Log Security 4702 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Windows Event Log Security 4698 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Windows Event Log Security 4688 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Sysmon EventID 1 | XmlWinEventLog |
XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
|
| CrowdStrike ProcessRollup2 | Other | crowdstrike:events:sensor |
crowdstrike |
| Windows Event Log Security 5145 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Sysmon EventID 12 | XmlWinEventLog |
XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
|
| Windows Event Log Security 4738 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Windows Event Log Security 4742 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Sysmon EventID 14 | XmlWinEventLog |
XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
|
| Windows Event Log Application 3000 | XmlWinEventLog |
XmlWinEventLog:Application |
|
| Windows Event Log TaskScheduler 200 | wineventlog |
WinEventLog:Microsoft-Windows-TaskScheduler/Operational |
|
| Windows Event Log TaskScheduler 201 | XmlWinEventLog |
XmlWinEventLog:Security |
References
- https://www.youtube.com/watch?v=dq2Hv7J9fvk
- http://resources.infosecinstitute.com/common-malware-persistence-mechanisms/
- https://www.fireeye.com/blog/threat-research/2010/07/malware-persistence-windows-registry.html
- https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html
- http://www.fuzzysecurity.com/tutorials/19.html
Source: GitHub | Version: 3