MSPs are implicitly trusted by their customers, many of whom subscribe to security services. This adversary abused that trust relationship, using desktop support software to connect to additional victims from the MSP's network.
-
-
Prikaži ovu nit
-
@elastic Endpoint Security's behavioral protections prevented process injection attempts that would have downloaded and executed ransomware.Prikaži ovu nit -
Understanding/baselining the use of admin tools, remote support software, and relationships with trusted third parties with access to your enterprise are functions every organization should perform.
Prikaži ovu nit -
@eventquerylang can be used to baseline your environment and detect & prevent unwanted behaviors. This EQL query matches a sequence of two related events - a process that is a descendant of ScreenConnect*.exe followed by network activity from the descendant process.pic.twitter.com/bfOheKgbpe
Prikaži ovu nit -
This query can easily be expanded to include other remote access software or filter expected activity in your environment. This example builds on the previous query by matching on additional remote support software and filters results where the process name is “trusted.exe”.pic.twitter.com/1LHMjcMI6Q
Prikaži ovu nit -
Monitoring for connection attempts by
#lolbins to plaintext hosting and sharing sites can be a high efficacy detection. This isn’t a comprehensive list of process names and domains, but can be expanded based on your understanding of normal behavior in your network.pic.twitter.com/WWEMYgeduX
Prikaži ovu nit -
Check out EQLlib for over 100 open source security analytics: https://eqllib.readthedocs.io/en/latest/analytics.html …
Prikaži ovu nit
Kraj razgovora
Novi razgovor -
-
-
Nice blog post! Question on it, what was the process that drops the batch file to disk? Cmd.exe or screenconnect*.exe powershell
-
I'm glad you enjoyed it
It was the ScreenConnect process that dropped the batch file to disk.
Kraj razgovora
Novi razgovor -
-
-
Nice write-up man! You mind DMing me? I have a couple questions and maybe some extra info for you.
-
Always a pleasure chewing the fat with you
Kraj razgovora
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.


