Carbanak+FIN7
|
The technique was not in scope.
|
APT29
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
20.B.3
|
|
|
A Technique alert detection (orange indicator) called "Create Account (Net Use Command)" was generated for net.exe with the command-line arguments to add the new user Toby.
[1]
|
|
Telemetry showed wsmprovhost.exe spawning net.exe with the command-line arguments to add the new user Toby.
[1]
|
|
Added a new user to the remote host Scranton (10.0.1.4) using net.exe
net.exe adding the user Toby
[1]
Added a new user to the remote host Scranton (10.0.1.4) using net.exe
net.exe adding the user Toby
[1]
APT3
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
7.A.1.1
|
|
Specific Behavior
(Configuration Change)
|
A Specific Behavior alert named \"New user account created\" was generated based on the Registry change identifying that the new user Jesse was created. A child event of the alert indicated that the account had been added to the local admins group (but did not identify the account creation specifically).
[1]
[2]
|
|
Added user Jesse to Conficker (10.0.0.5) through RDP connection
-
This alert was added to the capability's detection after the start of the evaluation, so the detection is identified as a configuration change. See Configuration page for details.
[1]
[2]