Indeed fun technique! It was not easy to translate DACL/SACL changes in Security Descriptor of event 4670
But thanks, now I can understand what's here happening:
🛡️Detection/hunting idea in comments:👇🏼
Have fun! 👍
I saw someone sharing the below gitlab repo, I haven’t tried it but it looks awesome!
👀 Checkout the audit_best_practices.rules files under Dataset directory. Auditd configuration with best practices and mapped to MITRE! 👏
https://t.co/ez8KNUo72E
Starting today, if you know one of the SIEM, EDR or Data Lake languages, you know them all!
Dear industry, please meet RootA https://t.co/hyqgt6uCXV
RootA is a public-domain language for collective cyber defense, created to make threat detection, incident response, and actor attribution simple. It acts as an open-source wrapper on top of most of the existing SIEM, EDR, XDR, and Data Lake query languages. If you learn the basics of RootA, you will be able to contribute to collective defense. And if you have mastered a specific SIEM language, with RootA and https://t.co/WtPgZuphqM you can speak them all.
Inspired by success of Yara and Sigma rules, RootA is focused on a broader applicability by a larger community of defenders.
RootA is expressed using YAML, a wide-spread, easy-to-write and human-readable format.
Use any query language for detection, https://t.co/WtPgZuphqM will take care of the translation.
Correlation support. Common correlations are supported by RootA in order to make detection logic harder to bypass by the attackers, more compute efficient and future proof.
Log sources can be explicitly or implicitly defined in the native query itself or in the customizable logsource field.
RootA syntax fully accommodates #OCSF and #Sigma providing maximum compatibility for Detection Engineers.
Threat Actor Timeline. While Actors change, behaviours often stay the same. RootA supports an additional threat intelligence layer for CERTs, NCSCs, ISACs, MDRs, and Defence Agencies, to coordinate defence faster and with greater precision.
Mapping to TTPs. Link detection logic to related tactics, techniques, and procedures in terms of MITRE ATT&CK®.
You can start writing RootA rules in any code editor that supports YAML. To translate RootA rules to other languages use https://t.co/WtPgZuphqM by building it from source https://t.co/cgjIWoQM6g or hosted online privately by SOC Prime since 2018 at https://t.co/A1vEp6dxvB
I am beyond grateful to everybody on SOC Prime team, our customers, friends, families and Sigma community for your ongoing support, belief, inspiration and feedback.
Special gratitude to Alex Bredikhin Ruslan Mikhalov Adam Swan and Roman Ranskyi for working on the language specification and designs together. Nothing is impossible!
Source https://t.co/05yBu8evlD
@cyb3rops your comment is very far from the truth my friend. I’ll drop some facts tomorrow. Maybe in some parallel reality you can state things like that, but in this timeline, on this planet, I publicly ask you to not spread misinformation about me and my team’s contribution to #sigma standard, evolution, especially the amount of rules. And don’t list me next to thieves who copycat products after using freemium for two years. I can back this claim up in court if needed.
1\ #ThreatHunting for APT abuse of Exchange
APT Exchange abuse has been a common theme with techniques ranging from:
> Compiled DLL OWA backdoors
> .req webshells
> EWS / Legacy auth abuse
> Log / File deletion
TL;DR below or check out the full blog 👇👇
https://t.co/aOYzJTnJzL
✅ Exploitation of 0⃣ day at the time?
✅ Web🐚s involved?
✅ DNS MiTM? 👨🏭
It can only mean one thing.
Volexity blog:
https://t.co/2n8ElFuepk
#threatintel#cve20221040#apt
I was able to access thousands of companies’ passwords on #Azure and run code on their VMs.
This includes access to Microsoft’s own credentials… 💣
Here’s HOW I did it.
This is the story of #SynLapse. (1/11)
Адаптований переклад бест практик по кіберзахисту в умовах війни з SANS Shields UP: Six Defensive Techniques to Make Your Attackers Cry: Russia and Ukraine Cyber Crisis. Прошу поширити всім хто долучений до ІТ в Україні.
https://t.co/Pz1nA4nvEj
@dsszzi@_CERT_UA@underdefense
📌My Quick and Dirty script for defenders to prepare @anyrun_app sandbox (cmdline/powerhell logging, #windows audit, #sysmon) and grab that logs after #malware execution for additional analysis and #sigma rules creation.
➡️https://t.co/jD1Sgn24pv
#blueteam#threathunting#DFIR
Pushed: https://t.co/YtBYvQVbGx The current message flow has multiple flaws that would need to be addressed before I would consider using this for real-life operations. Consider this a dirty POC. If only there was a mouse and C2 expert that could make this safe to use....
Senior Security Consultant @Jean_Maes_1994 gives us the first comprehensive resource about all things #relaying. This guide covers a range of techniques from most common to the lesser-known.
https://t.co/dtX02qtSP1
⚠️Following the dnspy[.]net case, here is a list of domains owned by the same threat actor. The campaign spreading backdoored installers is STILL ONGOING, and targeting several open source projects: ↘️ (h/t @sekoia_io) [1/6]
I’m a firm believer in the (cliche) adage, “Outcomes, not output.” It’s not about the number of lines of code you wrote in 2021, but the impact those lines of code had - the outcomes they created. Here’s 5 small things you can do in 2022 to create big AD security outcomes:
🧵
A user in the Bloodhound Slack asked a question about how they could start approaching the task of detecting BH (Sharphound) and it inspired me to write my thoughts on the matter. Since it is buried as a random thread in Slack, I figured I'd share it here as a thread.