Carbanak+FIN7
|
The subtechnique was not in scope.
|
APT29
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
20.B.3
|
|
|
Telemetry showed addition of the new user Toby.
[1]
|
|
An MSSP detection for Lateral Movement was generated containing evidence a new user was created on Scranton with name 'toby'."
[1]
[2]
|
|
Added a new user to the remote host Scranton (10.0.1.4) using net.exe
net.exe adding the user Toby
[1]
Added a new user to the remote host Scranton (10.0.1.4) using net.exe
net.exe adding the user Toby
[1]
[2]
APT3
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
7.A.1.1
|
|
Telemetry
(Configuration Change)
|
Telemetry showed data for account Jesse creation after configuration change to enable collection of event ID 4720.
[1]
|
|
Added user Jesse to Conficker (10.0.0.5) through RDP connection
-
Visibility of account creation data was verified in retesting at the end of the evaluation after vendor adjusted data collection configuration and visibility of account creation.
[1]