Anvilogic high experimental spl
Full Control Permissions Granted to Everyone - Windows [splunk-sysmon]
Adversaries may modify file or directory permissions/attributes to evade access control lists and access protected files. Windows implements file and directory ACLs as Discretionary Access Control Lists (DACLs). Adversaries can interact with the DACLs using built-in Windows commands which can grant adversaries higher permissions on specific files and folders. This use case detects commands assigning full control to Everyone which has been observed with Ryuk ransomware. -- Threat Actor Association: UNC5812 -- Atomics T1222.001 Test #2 Atomics T1222.001 Test #5
Detection Logic
`get_endpoint_data` `get_endpoint_data_sysmon` (TERM(EventCode=1)
OR "<EventID>1<") TERM(icacls)
OR ("/grant" "Everyone:F")
| regex process="(?i)\s+\/grant\s+everyone"
| table _time, host, user parent_*, process, process_*
| bin span=1s
| stats values(*) as * by _time, host Field Validations
Loading…
Comments (0)
Loading comments...