> For the complete documentation index, see [llms.txt](https://jacob-taylor.gitbook.io/security-analyst/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://jacob-taylor.gitbook.io/security-analyst/path-4/endpoint-security-monitoring/sysmon.md).

# Sysmon

Utilize Sysmon to monitor and log your endpoints and environments.

## <mark style="color:red;">Sysmon Overview</mark>

Sysmon (**System Monitor**) is a tool used to monitor and log Windows Events. This monitoring and logging solution is commonly used by enterprises as it has further detail and granular control that Windows Event Logs.&#x20;

Sysmon is a Windows system service and device driver that will remain resident across system reboots to monitor and log system activity to Windows event log by providing detailed information about process creations, network connections, and changes to file creation file. By collecting the generated events using Windows Event Collection or SIEM agents and subsequently analyzing them to identify malicious or anomalous activity and understand how intruders and malware operate on a network.

Additional to detailed and high-quality logs, Sysmon gathers event tracing that assists in identifying anomalies in the environment and will start early in the boot process.&#x20;

Events within Sysmon are stored in *`Applications and Services Logs/Microsoft/Windows/Sysmon/Operational`*

### <mark style="color:orange;">Sysmon Config Overview</mark>

A config file is required for Sysmon to tell the binary how to analyze the events it receives. This config file can be downloaded or created, such as the one [here](https://github.com/SwiftOnSecurity/sysmon-config). Sysmon includes 29 different types of Event IDs, all of which can be used within the config to specify how the events should be handled and analyzed.

A majority of rules in sysmon-config will exclude rather than include events which is noticable when creating or modifying configuration files. This helps to filter out normal activity in the environment to decrease events and alerts that may be manually audited or searched in a SIEM.&#x20;

Alternately, there are rulesets such as ION-Storm sysmon-config fork that takes a more proactive approach with it's ruleset by using considerable amount of include rules. Configuration preferences will vary depending on the SOC team so flexibility  is important when monitoring.

### <mark style="color:orange;">Event ID 1: Process Creation</mark>

This event will look for any processes that have been created to look for known suspicious processes or processes with typos that would be considered an anomaly. This event will use the CommandLine and Image XML tags.

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<ProcessCreate onmatch="exclude">
	 	<CommandLine condition="is">C:\Windows\system32\svchost.exe -k appmodel -p -s camsvc</CommandLine>
	</ProcessCreate>
</RuleGroup>
```

{% endcode %}

The code above is specifying the Event ID to pull from as well as what condition to look for. In this case, it is excluding the svchost.exe process from the event logs.

### <mark style="color:orange;">Event ID 3: Network Connection</mark>

The network connection event will look for events that occur remotely. This will include files and sources of suspicious binaries as well as opened ports. This event will use the Image and DestinationPort XML tags.

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<NetworkConnect onmatch="include">
	 	<Image condition="image">nmap.exe</Image>
	 	<DestinationPort name="Alert,Metasploit" condition="is">4444</DestinationPort>
	</NetworkConnect>
</RuleGroup>
```

{% endcode %}

This code snippet includes two ways to identify suspicious network connection activity. The first way will identify files transmitted over open ports. In this case, specifically looking for nmap.exe which will be reflected within the event logs. The second method identifies open ports and specifically port 4444 which is commonly used with Metasploit. If the condition is met an event will be created and ideally trigger an alert for the SOC to further investigate.

### <mark style="color:orange;">Event ID 7: Image Loaded</mark>

This event will look for DLLs loaded by processes, which is useful when hunting for DLL Injection and DLL Hijacking attacks. It is recommended to exercise caution when using this Event ID as it causes a high system load. This event will use the Image, Signed, ImageLoaded, and Signature XML tags.

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<ImageLoad onmatch="include">
	 	<ImageLoaded condition="contains">\Temp\</ImageLoaded>
	</ImageLoad>
</RuleGroup>
```

{% endcode %}

This ill look for any DLLs that have been loaded within the \Temp\ directory. If a DLL is loaded within this directory it can be considered an anomaly and should be further investigated.

### <mark style="color:orange;">Event ID 8: CreateRemoteThread</mark>

The CreateRemoteThread Event ID will monitor for processes injecting code into other processes. The CreateRemoteThread function is used for legitimate tasks and applications. However, it could be used by malware to hide malicious activity. This event will use the SourceImage, TargetImage, StartAddress, and StartFunction XML tags.

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<CreateRemoteThread onmatch="include">
	 	<StartAddress name="Alert,Cobalt Strike" condition="end with">0B80</StartAddress>
	 	<SourceImage condition="contains">\</SourceImage>
	</CreateRemoteThread>
</RuleGroup>
```

{% endcode %}

This code shows two ways of monitoring for CreateRemoteThread. The first method will look at the memory address for a specific ending condition which could be an indicator of a Cobalt Strike beacon. The second method will look for injected processes that do not have a parent process. This should be considered an anomaly and require further investigation.

### <mark style="color:orange;">Event ID 11: File Created</mark>

This event ID is will log events when files are created or overwritten the endpoint. This could be used to identify file names and signatures of files that are written to disk. This event uses TargetFilename XML tags.

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<FileCreate onmatch="include">
	 	<TargetFilename name="Alert,Ransomware" condition="contains">HELP_TO_SAVE_FILES</TargetFilename>
	</FileCreate>
</RuleGroup> 
```

{% endcode %}

The above code snippet is an example of a ransomware event monitor. This is just one example of a variety of different ways to utilize Event ID 11.

### <mark style="color:orange;">Event ID 12 / 13 / 14: Registry Event</mark>

This event looks for changes or modifications to the registry. Malicious activity from the registry can include persistence and credential abuse. This event uses TargetObject XML tags.

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<RegistryEvent onmatch="include">
	 	<TargetObject name="T1484" condition="contains">Windows\System\Scripts</TargetObject>
	</RegistryEvent>
</RuleGroup>
```

{% endcode %}

The above code snippet will look for registry objects that are in the *"Windows\System\Scripts"* directory as this is a common directory for adversaries to place scripts to establish persistence.

### <mark style="color:orange;">Event ID 15: FileCreateStreamHash</mark>

This event will look for any files created in an alternate data stream. This is a common technique used by adversaries to hide malware. This event uses TargetFilename XML tags.

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<FileCreateStreamHash onmatch="include">
	 	<TargetFilename condition="end with">.hta</TargetFilename>
	</FileCreateStreamHash>
</RuleGroup> 
```

{% endcode %}

The above code snippet will look for files with the .hta extension that have been placed within an alternate data stream.

### <mark style="color:orange;">Event ID 22: DNS Event</mark>

This event will log all DNS queries and events for analysis. The most common way to deal with these events is to exclude all trusted domains known to be very common "noise" in the environment. Once rid of the noise, look for DNS anomalies. This event uses QueryName XML tags.

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<DnsQuery onmatch="exclude">
	 	<QueryName condition="end with">.microsoft.com</QueryName>
	</DnsQuery>
</RuleGroup> 
```

{% endcode %}

The above code snippet will get exclude any DNS events with the .microsoft.com query. This will get rid of the noise within the environment. &#x20;

## <mark style="color:red;">Installing and Preparing Sysmon</mark>

### <mark style="color:orange;">Installing Sysmon</mark>

The installation for Sysmon only requires downloading the Sysmon binary from the [Microsoft Sysinternals](https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon) website.Moreover, download all of the Sysinternals tools with a PowerShell command instead of grabbing a single binary. It is also recommended to use a Sysmon config file along with Sysmon to get more detailed and high-quality event tracing.&#x20;

Download the [Microsoft Sysinternal Suite](https://docs.microsoft.com/en-us/sysinternals/downloads/sysinternals-suite) or use the below command to run a PowerShell module download and install all of the Sysinternals tools.&#x20;

PowerShell command: `Download-SysInternalsTools C:\Sysinternals`

To fully utilize Sysmon, download or creat aSysmon config: [SwiftOnSecurity sysmon-config](https://github.com/SwiftOnSecurity/sysmon-config).&#x20;

A Sysmon config will allow for further granular control over the logs as well as more detailed event tracing. These demonstrations will use both the SwiftOnSecurity configuration file as well as the [ION-Storm config file](https://github.com/ion-storm/sysmon-config/blob/develop/sysmonconfig-export.xml).&#x20;

### <mark style="color:orange;">Starting Sysmon</mark>

To start Sysmon, open a new PowerShell or Command Prompt as an Administrator. Run the below command to execute the Sysmon binary, accept the end-user license agreement, and use SwiftOnSecurity config file.&#x20;

Command Used: `Sysmon.exe -accepteula -i ..\Configuration\swift.xml`

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FlhVwlHpJICVvzbYtsxeZ%2Fimage.png?alt=media&amp;token=409dcc4b-d0ad-4e9f-a4ae-15aae45f9f3c" alt=""><figcaption><p>Powershell</p></figcaption></figure>

Now that Sysmon is started with the configuration file, look at the Event Viewer to monitor events. The event log is located under *`Applications and Services Logs/Microsoft/Windows/Sysmon/Operational`*

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FHTeKjTcOavMjBvpN2bbR%2Fimage.png?alt=media&amp;token=b661c80c-3750-4165-b3fd-85342f3866a2" alt=""><figcaption><p>Event Viewer</p></figcaption></figure>

*Note: At any time you can change the configuration file used by uninstalling or updating the current configuration and replacing it with a new configuration file. For more information look through the Sysmon help menu.*&#x20;

## <mark style="color:red;">Cutting out the Noise</mark>

### <mark style="color:orange;">Malicious Activity Overview</mark>

Most normal activity or "noise" seen on a network is excluded or filtered out with Sysmon, allowing for focus toward meaningful events to quickly identify and investigate suspicious activity. Best practice is to use multiple detections and techniques simultaneously in an effort to identify threats when actively monitoring a network.&#x20;

### <mark style="color:orange;">Sysmon "Best Practices"</mark>

Because Sysmon offers a fairly open and configurable platform, there are ways to implement practices to ensure efficient operations and not missing an potential threats.

* <mark style="color:blue;">Exclude > Include</mark>

<mark style="background-color:blue;">Prioritize excluding event rather than including events when creating Sysmon rules to prevent from accidentally missing crucial events and only seeing the events that matter the most.</mark>

* <mark style="color:purple;">CLI gives you further control</mark>

<mark style="background-color:purple;">CLI gives the most control and filtering allowing for further granular control. Use</mark> <mark style="background-color:purple;"></mark><mark style="background-color:purple;">`Get-WinEvent`</mark> <mark style="background-color:purple;"></mark><mark style="background-color:purple;">or</mark> <mark style="background-color:purple;"></mark><mark style="background-color:purple;">`wevutil.exe`</mark> <mark style="background-color:purple;"></mark><mark style="background-color:purple;">to access and filter logs. These tools will be less used/needed as Sysmon is incorporated into SIEMs and other detection solutions.</mark>

* <mark style="color:green;">Know the environment before implementation</mark>

<mark style="background-color:green;">When implementing a platform or tool, it is important to know your environment and have a firm understanding of the network for baselining activity and effectively crafting rules for suspicious activity.</mark>&#x20;

### <mark style="color:orange;">Filtering Events with Event Viewer</mark>

Event Viewer may not be the best for filtering events and out-of-the-box offers limited control over logs. The main filter used with Event Viewer filters the `EventID` and keywords and filter by writing XML can also be chosen but is a tedious process that doesn't scale well.

To open the filter menu select `Filter Current Log` from the Actions menu.&#x20;

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FhNwNB90VLLVJmIRpZ9Nw%2Fimage.png?alt=media&amp;token=175a886c-822d-4a1b-8ad9-d63e29ff123c" alt=""><figcaption><p>Filter Current Log</p></figcaption></figure>

If the filter menu is successfully opened, it should look like the menu below:

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FCBeAyt0qqDYIKMAN5gLq%2Fimage.png?alt=media&amp;token=aa664aab-ff80-4b1c-b307-777f10042c9f" alt=""><figcaption><p>Filter Menu</p></figcaption></figure>

From this menu, any filters or categories can be added.

### <mark style="color:orange;">Filtering Events with PowerShell</mark>

To view and filter events with PowerShell using `Get-WinEvent` along with `XPath` queries, use any XPath queries that can be found in the XML view of events. `wevutil.exe` will be used to view events once filtered. The command line is typically used over the Event Viewer GUI as it allows for further granular control and filtering whereas the GUI does not. For more information about using `Get-WinEvent`and `wevutil.exe` check out the [Windows Event Log ](https://jacob-taylor.gitbook.io/security-analyst/path-4/endpoint-security-monitoring/windows-event-logs)notes.

Filter by Event ID: `*/System/EventID=<ID>`

Filter by XML Attribute/Name: `*/EventData/Data[@Name="<XML Attribute/Name>"]`

Filter by Event Data: `*/EventData/Data=<Data>`

We can put these filters together with various attributes and data to get the most control out of our logs. Look below for an example of using `Get-WinEvent` to look for network connections coming from port 4444.

{% code overflow="wrap" %}

```powershell
Get-WinEvent -Path <Path to Log> -FilterXPath '*/System/EventID=3 and */EventData/Data[@Name="DestinationPort"] and */EventData/Data=4444'
```

{% endcode %}

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FchwukGn22TwKJzXuUaPL%2Fimage.png?alt=media&amp;token=4693b86c-1fc9-4d59-bff3-556af87d085d" alt=""><figcaption><p>Filtering Events</p></figcaption></figure>

***How many event ID 3 events are in C:\Users\THM-Analyst\Desktop\Scenarios\Practice\Filtering.evtx?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FVqLYwCQxF10qzTSCHYtT%2Fimage.png?alt=media&amp;token=20505b3d-af36-44c9-9180-3a0584908630" alt=""><figcaption><p>73591</p></figcaption></figure>

***What is the UTC time created of the first network event in C:\Users\THM-Analyst\Desktop\Scenarios\Practice\Filtering.evtx?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2Fqgl1YGaJTK4CmYgnVx9Y%2Fimage.png?alt=media&amp;token=0c08fda4-4e29-45cf-be9a-a6463d262a14" alt=""><figcaption></figcaption></figure>

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2F4n3xpM4CSLL0P0D4GX5W%2Fimage.png?alt=media&amp;token=05fb049e-7ea2-40dd-9eea-91b5d5fb8930" alt=""><figcaption><p>2021-01-06 01:35:50.464</p></figcaption></figure>

## <mark style="color:red;">Hunting Metasploit</mark>

### <mark style="color:orange;">Hunting Metasploit</mark>

Metasploit is an exploit framework used to run exploits on a machine for penetration testing and red team operations to connect back to a meterpreter shell. To hunt the meterpreter shell and it's functionality, begin looking for connections that originate from suspicious ports such as **4444** and **5555**. Metasploit using port **4444** by default and any IP connected to this port should be investigated. To begin an investigation, examine packet captures from the date of the log as well as suspicious processes that were created. This hunting method can be applied to other RATs and C2 beacons.

For more information about how malware and payloads interact with the network check out the [Malware Common Ports Spreadsheet](https://docs.google.com/spreadsheets/d/17pSTDNpa0sf6pHeRhusvWG6rThciE8CsXTSlDUAZDyo).

### <mark style="color:orange;">Hunting Network Connections</mark>

This modified Ion-Security configuration to detect the creation of new network connections and will use event ID 3 along with the destination port to identify active connections specifically connections on port `4444` and `5555`.&#x20;

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
<NetworkConnect onmatch="include">
<DestinationPort condition="is">4444</DestinationPort>
<DestinationPort condition="is">5555</DestinationPort>
</NetworkConnect>
</RuleGroup>
```

{% endcode %}

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FeNK6xNOYb8HtE3VPhvlC%2Fimage.png?alt=media&amp;token=8eb53b4e-f118-47e6-99eb-16d24a3f483d" alt=""><figcaption><p>Basic Metasploit payload being dropped onto the machine</p></figcaption></figure>

Now that the event is identified, it can provide some important information for further investigation like the `ProcessID` and `Image`.

### <mark style="color:orange;">Hunting for Open Ports with PowerShell</mark>

Powershell module **Get-WinEvent** and **XPath** queries can be used to hunt for open ports. The same queries used to filter out event from **NetworkConnect** with **DestinationPort** can use used in the instance.

`Get-WinEvent -Path -FilterXPath '*/System/EventID=3 and */EventData/Data[@Name="DestinationPort"] and */EventData/Data=4444'`

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FYFg374aVpiYLQBYUlNhH%2Fimage.png?alt=media&amp;token=6805ea36-72ef-4347-a469-6bbb963401b9" alt=""><figcaption></figcaption></figure>

**The script is first filtering by Event ID 3 which is the network connection ID. It is then filtering by the data name** (*in this case DestinationPort*) **as well as the specific port to filter. Adjust this syntax along with the events to get the data wanted in return.**

## <mark style="color:red;">Detecting Mimikatz</mark>

### <mark style="color:orange;">Detecting Mimikatz Overview</mark>

Although it is mainly known for dumping LSASS, Mimikatz is used to dump credentials from memory along with other Windows post-exploitation activity. Mimikatz creates a file, executes it from elevated process, creates a remote thread and other processes that can all be hunted. Anti-Virus typically finds the Mimikatz signature unless it is obfuscated or a dropper is used to get the file on to the device.

### <mark style="color:orange;">Detecting File Creation</mark>

To begin hunting for Mimikatz, look for files created with the the name "Mimikatz". This simple techniques allows for finding anything that might have bypassed Anti-Virus. While this technique is useful, dealing with an advanced threat will require more advanced techniques stuch as searching for LSASS behavior.

This is a very simple way of detecting Mimikatz activity that has bypassed AV or other detection measures.

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<FileCreate onmatch="include">
		<TargetFileName condition="contains">mimikatz</TargetFileName>
	</FileCreate>
</RuleGroup>
```

{% endcode %}

This method will not be commonly used to hunt for anomalies.

### <mark style="color:orange;">Hunting Abnormal LSASS Behavior</mark>

To hunt for abnormal LSASS behavior, use the *ProcessAccess* event ID as this event along with LSASS will shoiw potential LSASS abuse usually connected to Mimikatz or other credential dumping tools.

If LSASS is accessed by a process other than svchost.exe, it should be considered suspicious behavior and further investigated. To aid in the search, use a filter to look for processes besides svchost.exe. Sysmon will provide further details such as the file path the process originated from to help lead investigations.

Below is a snippet of the config that will aid in the hunt.

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<ProcessAccess onmatch="include">
	       <TargetImage condition="image">lsass.exe</TargetImage>
	</ProcessAccess>
</RuleGroup>
```

{% endcode %}

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2F5CfCnxxkGJh9dhz7FpNb%2Fimage.png?alt=media&amp;token=929692be-3d52-4cfe-9da9-5bd3120f0e37" alt=""><figcaption><p>Attack using an obfuscated version of Mimikatz to dump credentials from memory</p></figcaption></figure>

The event that has the Mimikatz process accessed but svchost.exe events are also shown. Alter the config to exclude events with the `SourceImage` event coming from svhost.exe.&#x20;

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<ProcessAccess onmatch="exclude">
		<SourceImage condition="image">svchost.exe</SourceImage>
	</ProcessAccess>
	<ProcessAccess onmatch="include">
		<TargetImage condition="image">lsass.exe</TargetImage>
	</ProcessAccess>
</RuleGroup>
```

{% endcode %}

Modifying the configuration file to include this exception to cut down events significantly and focus on only the anomalies is a technique can be used throughout Sysmon and events to cut down on "noise" in logs.

### <mark style="color:orange;">Detecting LSASS Behavior with PowerShell</mark>

Powershell module **Get-WinEvent** and **XPath** queries can be used to detect abnormal LSASS behavior. The same queries used to filter out other processes from `TargetImage` can use used in the instance as this alongside a well-built configuration file with a precise rule will do a lot of the heavy lifting.

`Get-WinEvent -Path -FilterXPath '*/System/EventID=10 and */EventData/Data[@Name="TargetImage"] and */EventData/Data="C:\Windows\system32\lsass.exe"'`

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FYliZSGtiO22H3IZxJv2m%2Fimage.png?alt=media&amp;token=2953cff2-0632-42ee-83c4-80af11e6c16e" alt=""><figcaption><p>Detecting Mimikatz with evtx</p></figcaption></figure>

## <mark style="color:red;">Hunting Malware</mark>

### <mark style="color:orange;">Hunting Malware Overview</mark>

Remote Access Trojans (RATs) are used to gain remote access to a machine and come with AV and detection evasion techniques. A RAT may use a Client-Server model and comes with an interface for easy user administration. Some RAT examples are `Xeexe` and `Quasar`.&#x20;

To detect and hunt malware, first identify the malware and ways to modify the configuration files as a technique called hypothesis-based hunting.

### <mark style="color:orange;">Hunting Rats and C2 Servers</mark>

One useful technique for detecting open ports on an endpoint that are known to be suspicious is to include them in logs. This will add to the hunting methodology as the logs can be used to identify adversaries on the network with the help of packet captures or other detection strategies for continued investigation.&#x20;

The code below is from the Ion-Storm configuration file which will alert when specific ports like `1034` and `1604` are being used as well as exclude common network connections like **OneDrive.** Excluding events will cut down on noise without missing anything.&#x20;

When using configuration files in a production environment, be careful and understand exactly what is happening within the configuration file an example of this is the Ion-Storm configuration file excludes port 53 as an event. Attackers and adversaries have begun to use port 53 as part of their malware/payloads which would go undetected if this this configuration file is blindly used as-is.

For more information about the ports that this configuration file alerts on check out this [spreadsheet](https://docs.google.com/spreadsheets/d/17pSTDNpa0sf6pHeRhusvWG6rThciE8CsXTSlDUAZDyo).

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<NetworkConnect onmatch="include">
		<DestinationPort condition="is">1034</DestinationPort>
		<DestinationPort condition="is">1604</DestinationPort>
	</NetworkConnect>
	<NetworkConnect onmatch="exclude">
		<Image condition="image">OneDrive.exe</Image>
	</NetworkConnect>
</RuleGroup>
```

{% endcode %}

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FEewl1TBgXDolsxrZDgfL%2Fimage.png?alt=media&amp;token=26803648-9465-419c-bd83-1dcfc4463781" alt=""><figcaption><p>Detecting a custom RAT that operates on port 8080</p></figcaption></figure>

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FRyPPuP9wkEA3VRDMmStw%2Fimage.png?alt=media&amp;token=7badbe74-e483-47e2-88d7-6f9965bc6447" alt=""><figcaption><p>Detecting a custom RAT that operates on port 8080</p></figcaption></figure>

### <mark style="color:orange;">Hunting for Common Back Connect Ports with PowerShell</mark>

`Get-WinEvent -Path -FilterXPath '*/System/EventID=3 and */EventData/Data[@Name="DestinationPort"] and */EventData/Data='`

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2F8rRTI5wxd3ZMevZJhxvO%2Fimage.png?alt=media&amp;token=c4ec0740-f06e-4dd1-8eef-8bda200b324f" alt=""><figcaption></figcaption></figure>

Powershell module **Get-WinEvent** and **XPath** queries can be used to filter events and gain granular control over logs. The same queries used to filter out event from **NetworkConnect** with **DestinationPort** can use used in the instance.

## <mark style="color:red;">Hunting Persistence</mark>

### <mark style="color:orange;">Persistence Overview</mark>

To maintain access to a compromised machine, an attacker will need to gain persistence which can be done in a multitude of ways. Sysmon can be used to hunt persistence by looking for File Creation and Registry Modification events.&#x20;

### <mark style="color:orange;">Hunting Startup Persistence</mark>

Below is a snippet of the config that will aid in event tracing for this technique looking at the SwiftOnSecurity detections for a file being placed in the `\Startup\` or `\Start Menu` directories.

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<FileCreate onmatch="include">
		<TargetFilename name="T1023" condition="contains">\Start Menu</TargetFilename>
		<TargetFilename name="T1165" condition="contains">\Startup\</TargetFilename>
	</FileCreate>
</RuleGroup>
```

{% endcode %}

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2Ffvoa1mvc3Jl7Zvvdf7nK%2Fimage.png?alt=media&amp;token=f7b5ede7-dcd3-40f9-9eda-72801d3fcc75" alt=""><figcaption><p>A live attack on the machine that involves persistence by adding a malicious EXE into the Startup folder.</p></figcaption></figure>

Via Event Viewer it is shown that `persist.exe` was placed in the `Startup` folder. Threat Actors will almost never be this obvious but any changes to the Start Menu should be investigated. Adjustments to the configuration file can be made to be more granular and create alerts past just the *File Created* tag.

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FV2DYAEuQBtFnOwMOrzLM%2Fimage.png?alt=media&amp;token=38bd289c-af94-4c4e-9848-d8a7ede6e1ed" alt=""><figcaption><p>Filtering by Event ID 11 or Rule Name T1023</p></figcaption></figure>

Once it has been identified that a suspicious binary or application has been placed in a startup location, an investigation can begin on the directory.

### <mark style="color:orange;">Hunting Registry Key Persistence</mark>

This SwiftOnSecurity detection looks for a registry modification that adjusts and places a script inside `CurrentVersion\Windows\Run` and other registry locations.

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<RegistryEvent onmatch="include">
		<TargetObject name="T1060,RunKey" condition="contains">CurrentVersion\Run</TargetObject>
		<TargetObject name="T1484" condition="contains">Group Policy\Scripts</TargetObject>
		<TargetObject name="T1060" condition="contains">CurrentVersion\Windows\Run</TargetObject>
	</RegistryEvent>
</RuleGroup>
```

{% endcode %}

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FVNOpI25Uh2nTW7m2qHs6%2Fimage.png?alt=media&amp;token=a5c01570-6a54-41fc-bcf7-1cc56666f153" alt=""><figcaption><p>An attack where the registry was modified to gain persistence</p></figcaption></figure>

Event logs show the registry was modified and `malicious.exe` was added to `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Persistence` while the **exe** can be found at `%windir%\System32\malicious.exe`

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2F7uzCndThF9IswKcFpoEY%2Fimage.png?alt=media&amp;token=386a1285-9680-449a-90c3-b9d3c39d5ae8" alt=""><figcaption></figcaption></figure>

Like the startup technique, filter by the `RuleName T1060` to make finding the anomaly easier.

To investigate this anomaly, look at the registry as well as the file location itself. Below is the registry area where the malicious registry key was placed.

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2F1DOkwHVVSpZjLS2n5DCK%2Fimage.png?alt=media&amp;token=5d2a52e7-d764-4a81-8c3a-4b19de92ae92" alt=""><figcaption><p><a href="https://i.imgur.com/d6hLTud.png">https://i.imgur.com/d6hLTud.png</a></p></figcaption></figure>

## <mark style="color:red;">Detecting Evasion Techniques</mark>

### <mark style="color:orange;">Evasion Techniques Overview</mark>

Examples of evasion techniques used by malware authors:

* **Alternate Data Streams** - Used to hid its files from normal inspection by saving the file in a different stream apart from `$DATA`
* **Injections** - Thread Hijacking, PE Injection, DLL Injection, etc
* Masquerading
* Packing/Compression
* Recompiling
* Obfuscation
* Anti-Reversing

Sysmon comes with an event ID to detect newly created and accessed streams allowing for quick detection and hunting malware that uses ADS.

DLL Injection and backdooring DLLs is done by taking an already used DLL used by an application and overwriting or including malicious code within the DLL.

### <mark style="color:orange;">Hunting Alternate Data Streams</mark>

Event ID 15 will hash and log any NTFS Streams included within the Sysmon configuration file, allowing for hunting malware that evades detections using ADS.&#x20;

The code snippet below will hunt for files in the `Temp` and `Startup` folder as well as `.hta` and `.bat` extension.

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<FileCreateStreamHash onmatch="include">
		<TargetFilename condition="contains">Downloads</TargetFilename>
		<TargetFilename condition="contains">Temp\7z</TargetFilename>
		<TargetFilename condition="ends with">.hta</TargetFilename>
		<TargetFilename condition="ends with">.bat</TargetFilename>
	</FileCreateStreamHash>
</RuleGroup>
```

{% endcode %}

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FqRrS1YWVLJaquf5nVzA7%2Fimage.png?alt=media&amp;token=10892467-01e2-4bb0-9661-ec813428f912" alt=""><figcaption></figcaption></figure>

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FdDHNTJAqpo4SMWC1mYUt%2Fimage.png?alt=media&amp;token=ca2bd480-b665-42e8-9f8f-de2b0d2047a0" alt=""><figcaption></figcaption></figure>

The event will show the location of the file name as well as the contents of the file this will be useful if an investigation is necessary.

### <mark style="color:orange;">Detecting Remote Threads</mark>

Adversaries' use of remote threads is common to evade detections alongside other techniques. Remote threads are created using Windows API `CreateRemoteThread` and can be accessed using `OpenThread` and `ResumeThread`. Knowing this, these techniques are used in evasion for DLL Injection, Thread Hijacking, and Process Hollowing.&#x20;

&#x20;The code snippet below uses Sysmon event ID 8 from the SwiftOnSecurity configuration rule which will exclude common remote threads without including any specific attributes this allows for a more open and precise event rule.

{% code overflow="wrap" %}

```xml
<RuleGroup name="" groupRelation="or">
	<CreateRemoteThread onmatch="exclude">
		<SourceImage condition="is">C:\Windows\system32\svchost.exe</SourceImage>
		<TargetImage condition="is">C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</TargetImage>
	</CreateRemoteThread>
</RuleGroup>
```

{% endcode %}

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FctSzaVH5ZXnwi56io9bs%2Fimage.png?alt=media&amp;token=71d99f75-0850-490c-a58a-153acce1e15e" alt=""><figcaption><p>Process Hollowing attack that abuses the notepad.exe process</p></figcaption></figure>

`powershell.exe` is creating a remote thread and accessing `notepad.exe`. This is an obvious PoC and could in theory execute any other kind of executable or DLL. The specific technique used in this example is called Reflective PE Injection.

### <mark style="color:orange;">Detecting Evasion Techniques with PowerShell</mark>

Powershell module **Get-WinEvent** and **XPath** queries can be used to filter and search for files that use an alternate data stream or create a remote thread. The same query only needs to filter by the `EventID` because the rule used within the configuration file is already doing a majority of the heavy lifting.&#x20;

*Detecting Remote Thread Creation*

&#x20;`Get-WinEvent -Path <Path to Log> -FilterXPath '*/System/EventID=8'`

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FesLCYGVisXMwxilH0HhO%2Fimage.png?alt=media&amp;token=466f212a-41e3-4681-bd54-06d920307ce0" alt=""><figcaption></figcaption></figure>

## <mark style="color:red;">Practical Investigations</mark>

### <mark style="color:green;">Investigation 1 - ugh, BILL THAT'S THE WRONG USB!</mark>

***What is the full registry key of the USB device calling svchost.exe in Investigation 1?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2F87lawaqJSOSDlaKfFjyM%2Fimage.png?alt=media&amp;token=a4c3f305-6050-4d99-988f-639d9f814ab2" alt=""><figcaption><p>HKLM\System\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&#x26;37c186b&#x26;0&#x26;STORAGE#VOLUME#_??_USBSTOR#DISK&#x26;VEN_SANDISK&#x26;PROD_U3_CRUZER_MICRO&#x26;REV_8.01#4054910EF19005B3&#x26;0#\FriendlyName</p></figcaption></figure>

***What is the device name when being called by RawAccessRead in Investigation 1?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FR5gPHrFvLobWRZQVgmiO%2Fimage.png?alt=media&amp;token=e474a4f1-c47f-43dd-adc6-546babec6b01" alt=""><figcaption><p>\Device\HarddiskVolume3</p></figcaption></figure>

***What is the first exe the process executes in Investigation 1?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FtMQV1wM4tvUB5TJUYzeK%2Fimage.png?alt=media&amp;token=d32751fc-6fbb-420b-b7cc-f8b4d521bcfd" alt=""><figcaption><p>rundll32.exe</p></figcaption></figure>

### <mark style="color:green;">Investigation 2 - This isn't an HTML file?</mark>

***What is the full path of the payload in Investigation 2?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FcFlGsQfV4odLKUfLlPfX%2Fimage.png?alt=media&amp;token=2691eeff-69f6-4068-9d49-5d5dea946c15" alt=""><figcaption><p>C:\Users\IEUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S97WTYG7\update.hta</p></figcaption></figure>

***What is the full path of the file the payload masked itself as in Investigation 2?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2F7O0T2kenwdFiTkShMI8b%2Fimage.png?alt=media&amp;token=e0c12cd2-0b37-4870-be61-fedd4af52e24" alt=""><figcaption><p>C:\Users\IEUser\Downloads\update.html</p></figcaption></figure>

***What signed binary executed the payload in Investigation 2?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2F8UDZq2YsF5rAntl6C8CM%2Fimage.png?alt=media&amp;token=568887fe-4de2-4c1a-bdb5-f96f041e4d2c" alt=""><figcaption><p>C:\Windows\System32\mshta.exe</p></figcaption></figure>

***What is the IP of the adversary in Investigation 2?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2F5ZytmwOKEY5nBa0ETNlO%2Fimage.png?alt=media&amp;token=19b90ba7-4b4e-42b4-9f02-687008732a4f" alt=""><figcaption><p>10.0.2.18</p></figcaption></figure>

***What back connect port is used in Investigation 2?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FyXIwE87HgoXFRDfsdyyt%2Fimage.png?alt=media&amp;token=7250dfd7-7d74-4407-a685-7e2f687d2250" alt=""><figcaption><p>4443</p></figcaption></figure>

### <mark style="color:green;">Investigation 3.1 - 3.2 - Where's the bouncer when you need him</mark>

***What is the IP of the suspected adversary in Investigation 3.1?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FLzWlvNxKT40Ei391oMkr%2Fimage.png?alt=media&amp;token=68370801-5e79-4eb9-a7c9-7dfc760ff7cd" alt=""><figcaption><p>172.30.1.253</p></figcaption></figure>

***What is the hostname of the affected endpoint in Investigation 3.1?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2Ff8y7FT7e16FiokCfPZG3%2Fimage.png?alt=media&amp;token=e3d42944-f826-4d26-a8f9-a9b380d6e74e" alt=""><figcaption><p>DESKTOP-O153T4R</p></figcaption></figure>

***What is the hostname of the C2 server connecting to the endpoint in Investigation 3.1?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FpIhcmqlsg3UpeAjEZL8M%2Fimage.png?alt=media&amp;token=d5449a67-280f-4c56-8cb6-d8bc65d11be2" alt=""><figcaption><p>empirec2</p></figcaption></figure>

***Where in the registry was the payload stored in Investigation 3.1?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2Fx5nBSRrDhAQ15xaIvEOv%2Fimage.png?alt=media&amp;token=9b24dfaf-1bd0-4307-9d4b-fe0210d1df5c" alt=""><figcaption><p>HKLM\SOFTWARE\Microsoft\Network\debug</p></figcaption></figure>

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FiZRRhDO7LPxIA1uFreLZ%2Fimage.png?alt=media&amp;token=6c9e7815-5d72-401e-9387-8da83b37af01" alt=""><figcaption><p>HKLM\SOFTWARE\Microsoft\Network\debug</p></figcaption></figure>

***What PowerShell launch code was used to launch the payload in Investigation 3.1?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FeDivq6Ju2R7a63ZDzO03%2Fimage.png?alt=media&amp;token=451934f1-8930-47af-83ec-809127aa9a12" alt=""><figcaption><p>"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -c "$x=$((gp HKLM:Software\Microsoft\Network debug).debug);start -Win Hidden -A "-enc $x" powershell";exit;</p></figcaption></figure>

***What is the IP of the adversary in Investigation 3.2?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2Fn22mUP3Oxz7Dm9JfKURE%2Fimage.png?alt=media&amp;token=04f9dd31-9fa3-45e4-bb38-d042293083b4" alt=""><figcaption><p>172.168.103.188</p></figcaption></figure>

***What is the full path of the payload location in Investigation 3.2?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FvELiKcs5xISeJU73cZPw%2Fimage.png?alt=media&amp;token=cd097dd8-4a6d-4ebe-8c0a-ade737aa639f" alt=""><figcaption><p>c:\users\q\AppData:blah.txt</p></figcaption></figure>

***What was the full command used to create the scheduled task in Investigation 3.2?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FgkK7rY9Lbet8anL4nCr8%2Fimage.png?alt=media&amp;token=d4ddc9b7-dc37-4717-a4e0-f8371c810233" alt=""><figcaption><p>"C:\WINDOWS\system32\schtasks.exe" /Create /F /SC DAILY /ST 09:00 /TN Updater /TR "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NonI -W hidden -c "IEX ([Text.Encoding]::UNICODE.GetString([Convert]::FromBase64String($(cmd /c ''more &#x3C; c:\users\q\AppData:blah.txt'''))))""</p></figcaption></figure>

***What process was accessed by schtasks.exe that would be considered suspicious behavior in Investigation 3.2?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FYTvFu8kGWjgRBWfjxede%2Fimage.png?alt=media&amp;token=a77a4025-9151-4376-990a-6b5847be4fb8" alt=""><figcaption><p>lsass.exe</p></figcaption></figure>

### <mark style="color:green;">Investigation 4 - Mom look! I built a botnet!</mark>

***What is the IP of the adversary in Investigation 4?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2F11As5DJzhxnPiIx5PFxe%2Fimage.png?alt=media&amp;token=7b9ba808-ab98-4cf1-ad3d-921553a9e2eb" alt=""><figcaption><p>172.30.1.253</p></figcaption></figure>

***What port is the adversary operating on in Investigation 4?***

![](https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FtY3rmEKumzoA00qFekjD%2Fimage.png?alt=media\&token=0399fc97-e8f8-487a-a5ec-fb8768e45840)

***What C2 is the adversary utilizing in Investigation 4?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FWSilr3vM6AIRTDp1Cfpi%2Fimage.png?alt=media&amp;token=35dd0682-5f40-4431-90a8-31b2094ff2d1" alt=""><figcaption><p>empire</p></figcaption></figure>
