Anvilogic high experimental spl

Full Control Permissions Granted to Everyone - Windows [splunk-sysmon]

Adversaries may modify file or directory permissions/attributes to evade access control lists and access protected files. Windows implements file and directory ACLs as Discretionary Access Control Lists (DACLs). Adversaries can interact with the DACLs using built-in Windows commands which can grant adversaries higher permissions on specific files and folders. This use case detects commands assigning full control to Everyone which has been observed with Ryuk ransomware. -- Threat Actor Association: UNC5812 -- Atomics T1222.001 Test #2 Atomics T1222.001 Test #5

View Source

Detection Logic

`get_endpoint_data` `get_endpoint_data_sysmon` (TERM(EventCode=1) 
OR "<EventID>1<") TERM(icacls) 
OR ("/grant" "Everyone:F")
| regex process="(?i)\s+\/grant\s+everyone"
| table _time, host, user parent_*, process, process_*
| bin span=1s
| stats values(*) as * by _time, host

Field Validations

Loading…

Comments (0)

Loading comments...