Anvilogic high experimental other
Full Control Permissions Granted to Everyone - Windows [snowflake-crowdstrikefdr_process]
Adversaries may modify file or directory permissions/attributes to evade access control lists and access protected files. Windows implements file and directory ACLs as Discretionary Access Control Lists (DACLs). Adversaries can interact with the DACLs using built-in Windows commands which can grant adversaries higher permissions on specific files and folders. This use case detects commands assigning full control to Everyone which has been observed with Ryuk ransomware. -- Threat Actor Association: UNC5812 -- Atomics T1222.001 Test #2 Atomics T1222.001 Test #5
Detection Logic
select * from crowdstrikefdr_process where event_time > dateadd(hour, -2, sysdate()) and event_platform ilike '%Win%' and regexp_like(process, '.*\\\s+\\\/grant\\\s+everyone.*', 'i') Field Validations
Loading…
Comments (0)
Loading comments...