Analysis on legit tools abused in human-operated ransomware
SANS Ransomware Summit 2023
Analysis on legit tools abused in human-operated ransomware
Speakers:
Toru Yamashige, Senior Incident Response Consultant, Trend Micro Inc.
Keisuke Tanaka, Principal Incident Response Consultant, Trend Micro Inc.
As the detection logics of AV vendors improve, threat actors employ countermeasures to evade them. One of the most common ways in which threat actors hide from detection and carry out their malicious activities is by abusing legitimate tools. We believe that “legitimate tools“ can be classified into three categories below, with a marked increase in the number of cases in which “commercial tools“ are being abused: - MS native tools, such as PsExec, PowerShell, and WMI. - Legitimate penetration testing tools, including Cobalt Strike, Metasploit, and Mimikatz. - Commercial tools, such as Atera, AnyDesk, and Splashtop. Regarding MS native tools, techniques such as LOLBAS and LOLBIN are well-researched, while AV vendors are making efforts to detect penetration testing tools. We feel that threat actors are likely to abuse commercial tools these days as the tools are highly functional and commonly used in corporate operations. There is, however, little research on the exact functionalities of these tools, the traces they leave behind when abused, and countermeasures to prevent such abuse. Therefor, in this presentation, we will focus on actual incident cases where commercial tools were abused and try to explain the details based on the following three points: Chapter 1: Introducing actual incident response cases we have supported in which commercial tools were abused and describing their functionalities. Chapter 2: Explaining the traces and artifacts left behind when the tools are abused in an attack, so that the audience can use this information in their actual incident response investigations. Chapter 3: Describing effective countermeasures against attacks that exploit the tool, which will be useful for containment during incident response and for considerations during normal operations.
View upcoming Summits:
1 view
161
34
6 months ago 00:00:01 4
С заботой о себе “НОВАЯ ЖИЗНЬ“
6 months ago 00:14:27 1
So THAT’S What’s REALLY Behind These College Protests | Redacted with Natali Morris
6 months ago 00:00:06 1
️ Highly recommended: Geopolitics Live, one of the fastest-growing and most quoted political Telegram channels in English
6 months ago 00:03:23 17
RUSSIA REVENGES WITH STRIKES ON DECISION MAKING CENTRE
6 months ago 00:06:41 1
Imperial presidency: Trump lays out plan to enlist military in deporting millions
6 months ago 00:09:32 1
Google Maps Data Scraping with Business Emails | Supports Multiple Keywords at Once!
6 months ago 00:06:21 1
Vantage Review: : The Unfiltered Truth about Vantage FX Broker!🔴
6 months ago 00:12:26 1
Good Game in Dry Heat: 4-Player Free-for-All Soviet vs. Yuri Online Multiplayer Red Alert 2 Gameplay
6 months ago 00:55:53 1
Ukraine’s logistical nightmare, Russian progress on the battlefield, Middle East Crisis, Georgia..
6 months ago 00:35:28 1
🤔Learn English with the TV show Friends! 📺| LEARN ENGLISH SPEAKING | English with Rachel’s English
6 months ago 00:07:01 1
Crypto Game | Play to Earn Games 2024 | Make Money Games
6 months ago 00:06:32 1
Migrant crisis: Ireland push EMERGENCY legislation after INFLUX of asylum seekers crossing border
6 months ago 00:01:32 1
PAULO MIYAO BREAKS DOWN THE BARATOPLATA
6 months ago 00:00:11 1
What is Zoro’s devil fruit ?? #onepiece #devilfruit
6 months ago 01:24:28 1
That’s it! Last chance for PEACE before NATO and Putin start full war | Redacted w Clayton Morris
6 months ago 00:27:38 1
Official denial
6 months ago 00:14:03 1
THEY changed it to TRICK YOU - the ORIGINAL story of The Little Mermaid
6 months ago 01:58:16 1
Patrick Christys Tonight | Monday 8th April
6 months ago 00:02:58 1
Almost X-Flare - Region 3654 Unleashed an Solar Flare
6 months ago 00:15:40 1
Finally Hearing LAGWAGON! Bass Teacher REACTS to “Give It Back”
6 months ago 00:03:33 1
Russia Captures US Armoured Vehicles Based On Famous Abrams Tank, Says Ukraine Abandoned Them
6 months ago 00:03:43 1
Russia Mocks USA With Video Of Abrams Tank Being Taken From Ukraine’s Avdiivka To Be Shown As Trophy
6 months ago 01:13:59 1
Tony Blinken’s Stern Warning to China| More Hubris!
6 months ago 00:14:59 1
Blinken says China helping fuel Russian threat to Ukraine | BBC News