Anvilogic high experimental other

Full Control Permissions Granted to Everyone - Windows [snowflake-crowdstrikefdr_process]

Adversaries may modify file or directory permissions/attributes to evade access control lists and access protected files. Windows implements file and directory ACLs as Discretionary Access Control Lists (DACLs). Adversaries can interact with the DACLs using built-in Windows commands which can grant adversaries higher permissions on specific files and folders. This use case detects commands assigning full control to Everyone which has been observed with Ryuk ransomware. -- Threat Actor Association: UNC5812 -- Atomics T1222.001 Test #2 Atomics T1222.001 Test #5

View Source

Detection Logic

select * from crowdstrikefdr_process where event_time > dateadd(hour, -2, sysdate()) and event_platform ilike '%Win%' and regexp_like(process, '.*\\\s+\\\/grant\\\s+everyone.*', 'i')

Field Validations

Loading…

Comments (0)

Loading comments...