Windows VSSVC Process Accessing Defender Engine: endpointEndpointNoneversion:1
Detects vssvc.exe opening a handle to MsMpEng.exe.
In the RedSun exploit, VSS participates in the cloud-file restore race that directs WD to write through the NTFS junction.
This handle acquisition is observed at the exact moment of exploitation.
vssvc querying MsMpEng is not expected in normal operation.
Windows Cloud Files Filter Log Created by Non-System Process: endpointEndpointNoneversion:1
Detects a non-system process causing creation of CldFlt0.etl under C:\Windows\System32\LogFiles\CloudFiles\.
This path is initialised by the CldFlt driver when a process calls CfRegisterSyncRoot() or CfConnectSyncRoot().
In the RedSun exploit this is a side-effect of the DoCloudStuff() function that registers a fake sync provider to create the cloud-tagged bait file.
Legitimate cloud providers (OneDrive etc.) register sync roots from SYSTEM-level service processes, not from user-context executables.
Windows Suspicious Child Process of TieringEngineService.exe: endpointEndpointNoneversion:1
Detects the RedSun privilege escalation exploit delivering a SYSTEM-level shell to the attacker's session.
RedSun replaces the legitimate TieringEngineService.exe with a malicious binary, which launches a process as SYSTEM, usually some sort of shell or shell spawner (conhost.exe, cmd.exe, PowerShell, etc.) in the attacker's active session.
Windows Cloud Files Filter Loaded by Uncommon Process: endpointEndpointNoneversion:1
The following analytic detects cldapi.dll being loaded by a process not associated with legitimate cloud sync activity.
The Windows Cloud Files API (cldapi.dll) is abused by several local privilege escalation exploits.
Windows Non-System Process Querying Definition Update: endpointEndpointNoneversion:1
Detects DNS queries to definitionupdates.microsoft.com or the go.microsoft.com fwlink redirect used for WD update downloads, when the querying process is not a Windows system component. BlueHammer utilizes these definition updates as part of its exploit chain.
Windows MsMpEng Writing to System32: endpointEndpointNoneversion:1
Detects MsMpEng.exe creating a file in C:\\Windows\\System32\\.
This should never happen under normal operation Windows Defender does not install kernel drivers at runtime.
In the BlueHammer exploit, the TOCTOU race causes MsMpEng (SYSTEM) to write the attacker's driver payload directly into the drivers directory.