This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Windows Filtering Platform Blocked Connection From EDR Agent Binary
Original Source:
[Sigma source]
Title:
Windows Filtering Platform Blocked Connection From EDR Agent Binary
Status:
test
Description:
Detects a Windows Filtering Platform (WFP) blocked connection event involving common Endpoint Detection and Response (EDR) agents. Adversaries may use WFP filters to prevent Endpoint Detection and Response (EDR) agents from reporting security events.
References:
-https://github.com/netero1010/EDRSilencer
-https://github.com/amjcyber/EDRNoiseMaker
-https://ghoulsec.medium.com/misc-series-4-forensics-on-edrsilencer-events-428b20b3f983
Author:
@gott_cyber
Date:
2024-01-08
modified:
None
Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
product: windows
service: security
definition: Requirements: Audit Filtering Platform Connection needs to be enabled
Detection:
selection:
EventID
:
'5157'
Application|endswith
:
-'\AmSvc.exe'
-'\cb.exe'
-'\CETASvc.exe'
-'\CNTAoSMgr.exe'
-'\CrAmTray.exe'
-'\CrsSvc.exe'
-'\CSFalconContainer.exe'
-'\CSFalconService.exe'
-'\CybereasonAV.exe'
-'\CylanceSvc.exe'
-'\cyserver.exe'
-'\CyveraService.exe'
-'\CyvrFsFlt.exe'
-'\EIConnector.exe'
-'\elastic-agent.exe'
-'\elastic-endpoint.exe'
-'\EndpointBasecamp.exe'
-'\ExecutionPreventionSvc.exe'
-'\filebeat.exe'
-'\fortiedr.exe'
-'\hmpalert.exe'
-'\hurukai.exe'
-'\LogProcessorService.exe'
-'\mcsagent.exe'
-'\mcsclient.exe'
-'\MsMpEng.exe'
-'\MsSense.exe'
-'\Ntrtscan.exe'
-'\PccNTMon.exe'
-'\QualysAgent.exe'
-'\RepMgr.exe'
-'\RepUtils.exe'
-'\RepUx.exe'
-'\RepWAV.exe'
-'\RepWSC.exe'
-'\sedservice.exe'
-'\SenseCncProxy.exe'
-'\SenseIR.exe'
-'\SenseNdr.exe'
-'\SenseSampleUploader.exe'
-'\SentinelAgent.exe'
-'\SentinelAgentWorker.exe'
-'\SentinelBrowserNativeHost.exe'
-'\SentinelHelperService.exe'
-'\SentinelServiceHost.exe'
-'\SentinelStaticEngine.exe'
-'\SentinelStaticEngineScanner.exe'
-'\sfc.exe'
-'\sophos ui.exe'
-'\sophosfilescanner.exe'
-'\sophosfs.exe'
-'\sophoshealth.exe'
-'\sophosips.exe'
-'\sophosLivequeryservice.exe'
-'\sophosnetfilter.exe'
-'\sophosntpservice.exe'
-'\sophososquery.exe'
-'\sspservice.exe'
-'\TaniumClient.exe'
-'\TaniumCX.exe'
-'\TaniumDetectEngine.exe'
-'\TMBMSRV.exe'
-'\TmCCSF.exe'
-'\TmListen.exe'
-'\TmWSCSvc.exe'
-'\Traps.exe'
-'\winlogbeat.exe'
-'\WSCommunicator.exe'
-'\xagt.exe'
condition
:
selection
Falsepositives:
-Unlikely
Level:
high