Analysis on legit tools abused in human-operated ransomware
SANS Ransomware Summit 2023
Analysis on legit tools abused in human-operated ransomware
Speakers:
Toru Yamashige, Senior Incident Response Consultant, Trend Micro Inc.
Keisuke Tanaka, Principal Incident Response Consultant, Trend Micro Inc.
As the detection logics of AV vendors improve, threat actors employ countermeasures to evade them. One of the most common ways in which threat actors hide from detection and carry out their malicious activities is by abusing legitimate tools. We believe that “legitimate tools“ can be classified into three categories below, with a marked increase in the number of cases in which “commercial tools“ are being abused: - MS native tools, such as PsExec, PowerShell, and WMI. - Legitimate penetration testing tools, including Cobalt Strike, Metasploit, and Mimikatz. - Commercial tools, such as Atera, AnyDesk, and Splashtop. Regarding MS native tools, techniques such as LOLBAS and LOLBIN are well-researched, while AV vendors are making efforts to detect penetration testing tools. We feel that threat actors are likely to abuse commercial tools these days as the tools are highly functional and commonly used in corporate operations. There is, however, little research on the exact functionalities of these tools, the traces they leave behind when abused, and countermeasures to prevent such abuse. Therefor, in this presentation, we will focus on actual incident cases where commercial tools were abused and try to explain the details based on the following three points: Chapter 1: Introducing actual incident response cases we have supported in which commercial tools were abused and describing their functionalities. Chapter 2: Explaining the traces and artifacts left behind when the tools are abused in an attack, so that the audience can use this information in their actual incident response investigations. Chapter 3: Describing effective countermeasures against attacks that exploit the tool, which will be useful for containment during incident response and for considerations during normal operations.
View upcoming Summits:
1 view
213
45
2 weeks ago 00:00:00 1
LIVE | ’F**K Netanyahu’: Trump Shocks Israel Amid War | No Jan Oath Day Invite For Bibi?
2 weeks ago 00:00:00 1
LIVE | IDF’s Biggest Admission On Houthi Attacks: Yemen Rains 40 Ballistic Missiles On Israel
2 weeks ago 00:01:57 55
Trump Threatens Denmark With Tariffs Over Greenland
2 weeks ago 00:52:05 2
Russia Advancing on All Fronts: Toretsk Hangs by a Thread w/Patrick Henningsen
2 weeks ago 00:29:01 9
’GET OUT NOW’: California residents devastated by catastrophic wildfires
3 weeks ago 00:00:00 11
LIVE | Putin Kicks Off Orthodox Christmas Celebrations; Attends Mass In Moscow | Watch
3 weeks ago 00:08:18 1
CoinTech2U vs Bitget : Which Platform Is Better for Your Trading Journey?
3 weeks ago 00:03:48 13
Putin’s Deadly Start To 2025: Russia’s Week-Long Assault Cripples Ukraine; 12000+ Troops Wiped Out
3 weeks ago 00:13:51 1
Douglas Macgregor: Russia Destroys NATO Brigade in Pokrovsk - Mass Desertion, Commander’s Death!
3 weeks ago 00:03:57 1
Greg Secker Exposed: Is Smartcharts Legit or a Scam?
3 weeks ago 00:07:58 1
What do Russians want in 2025? | BBC News
3 weeks ago 00:06:31 1
Joe Biden will most likely outlive Trump, even though he’s older
3 weeks ago 00:09:47 3
’We Were Brainwashed’: Foreign Fighters Flee in Protest - Ukraine’s Command Accused of Atrocities
3 weeks ago 00:09:23 2
Aryna Sabalenka v Yulia Putintseva - Brisbane International Highlights | Wide World of Sports
3 weeks ago 00:09:22 37
Biden says New Orleans attacker who killed 15 was inspired by Islamic State group | BBC News
3 weeks ago 00:14:01 1
Secret Negotiations In The USA🤫Russians Approach Yantarne⚔️ Military Summary And Analysis
3 weeks ago 00:03:03 1
GNSS SNR
3 weeks ago 00:10:03 1
SHOCK Confession Of New Syrian Leader Triggers Global Alarm!
4 weeks ago 00:06:48 1
Apollo vs. Leads Sniper: The Ultimate Lead Generation Tools Showdown! 👌
4 weeks ago 00:07:03 1
SmartCharts Review : Is This the Best Trading Platform for Beginners?
4 weeks ago 00:00:00 15
LIVE | U.S.’ THAAD ’Intercepts’ Houthi Missile For 1st Time As Israel Fights 10th Attack From Yemen
4 weeks ago 00:08:02 1
Krystal and Saagar: MSNBC ENRICHES Never Trump Grifters, Mary Trump Book Sales EXPLODE
4 weeks ago 00:05:52 1
Bot Trading : Is CoinTech2U the Key to Financial Freedom?