Windows Filtering Platform Blocked Connection From EDR Agent Binary

 Original Source: [Sigma source]
Title: Windows Filtering Platform Blocked Connection From EDR Agent Binary
Status: test
Description:Detects a Windows Filtering Platform (WFP) blocked connection event involving common Endpoint Detection and Response (EDR) agents. Adversaries may use WFP filters to prevent Endpoint Detection and Response (EDR) agents from reporting security events.
References:
  -https://github.com/netero1010/EDRSilencer
  -https://github.com/amjcyber/EDRNoiseMaker
  -https://ghoulsec.medium.com/misc-series-4-forensics-on-edrsilencer-events-428b20b3f983
Author: @gott_cyber
Date: 2024-01-08
modified:None
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • product: windows
  • service: security
  • definition: Requirements: Audit Filtering Platform Connection needs to be enabled
Detection:
  selection:
    EventID: '5157'
    Application|endswith:
      -'\AmSvc.exe'
      -'\cb.exe'
      -'\CETASvc.exe'
      -'\CNTAoSMgr.exe'
      -'\CrAmTray.exe'
      -'\CrsSvc.exe'
      -'\CSFalconContainer.exe'
      -'\CSFalconService.exe'
      -'\CybereasonAV.exe'
      -'\CylanceSvc.exe'
      -'\cyserver.exe'
      -'\CyveraService.exe'
      -'\CyvrFsFlt.exe'
      -'\EIConnector.exe'
      -'\elastic-agent.exe'
      -'\elastic-endpoint.exe'
      -'\EndpointBasecamp.exe'
      -'\ExecutionPreventionSvc.exe'
      -'\filebeat.exe'
      -'\fortiedr.exe'
      -'\hmpalert.exe'
      -'\hurukai.exe'
      -'\LogProcessorService.exe'
      -'\mcsagent.exe'
      -'\mcsclient.exe'
      -'\MsMpEng.exe'
      -'\MsSense.exe'
      -'\Ntrtscan.exe'
      -'\PccNTMon.exe'
      -'\QualysAgent.exe'
      -'\RepMgr.exe'
      -'\RepUtils.exe'
      -'\RepUx.exe'
      -'\RepWAV.exe'
      -'\RepWSC.exe'
      -'\sedservice.exe'
      -'\SenseCncProxy.exe'
      -'\SenseIR.exe'
      -'\SenseNdr.exe'
      -'\SenseSampleUploader.exe'
      -'\SentinelAgent.exe'
      -'\SentinelAgentWorker.exe'
      -'\SentinelBrowserNativeHost.exe'
      -'\SentinelHelperService.exe'
      -'\SentinelServiceHost.exe'
      -'\SentinelStaticEngine.exe'
      -'\SentinelStaticEngineScanner.exe'
      -'\sfc.exe'
      -'\sophos ui.exe'
      -'\sophosfilescanner.exe'
      -'\sophosfs.exe'
      -'\sophoshealth.exe'
      -'\sophosips.exe'
      -'\sophosLivequeryservice.exe'
      -'\sophosnetfilter.exe'
      -'\sophosntpservice.exe'
      -'\sophososquery.exe'
      -'\sspservice.exe'
      -'\TaniumClient.exe'
      -'\TaniumCX.exe'
      -'\TaniumDetectEngine.exe'
      -'\TMBMSRV.exe'
      -'\TmCCSF.exe'
      -'\TmListen.exe'
      -'\TmWSCSvc.exe'
      -'\Traps.exe'
      -'\winlogbeat.exe'
      -'\WSCommunicator.exe'
      -'\xagt.exe'

  condition:selection
Falsepositives:
  -Unlikely
Level: high