Carbanak+FIN7
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
1.A.8
|
|
|
|
|
A Technique detection named "Command-Line Interface (Office Parent)" was generated when wscript.exe spawned cmd.exe from a process tree that included winword.exe.
[1]
|
Tactic
(Configuration Change (Detection Logic))
|
A Tactic detection named "Scripting (Process)" was generated when wscript.exe spawned cmd.exe.
[1]
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "Command-Line Interface (Process)" was generated when wscript.exe spawned cmd.exe.
[1]
|
General
(Configuration Change (Detection Logic))
|
A General detection named "Living Off The Land Binaries (LOLBAS)" was generated when wscript.exe spawned cmd.exe.
[1]
|
|
2.B.2
|
|
|
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "Command-Line Interface (Process)" was generated when wscript.exe spawned cmd.exe.
[1]
|
General
(Configuration Change (Detection Logic))
|
A General detection named "Living Off The Land Binaries (LOLBAS)" was generated when wscript.exe spawned cmd.exe.
[1]
|
Tactic
(Configuration Change (Detection Logic))
|
A Tactic detection named "Scripting (Process)" was generated when wscript.exe spawned cmd.exe.
[1]
|
|
3.A.1
|
|
Tactic
(Configuration Change (Detection Logic))
|
A Tactic detection named "Scripting (Process)" was generated when wscript.exe spawns cmd.exe.
[1]
|
|
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "Command-Line Interface (Process)" was generated when wscript.exe spawned cmd.exe.
[1]
|
General
(Configuration Change (Detection Logic))
|
A General detection named "Living Off The Land Binaries (LOLBAS)" was generated when wscript.exe spawned cmd.exe.
[1]
|
|
3.B.2
|
|
|
|
General
(Configuration Change (Detection Logic))
|
A General detection named "Living Off The Land Binaries (LOLBAS)" was generated when wscript.exe spawned cmd.exe.
[1]
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "Command-Line Interface (Process)" was generated when wscript.exe spawned cmd.exe.
[1]
|
Tactic
(Configuration Change (Detection Logic))
|
A Tactic detection named "Scripting (Process)" was generated when wscript.exe spawned cmd.exe.
[1]
|
|
4.B.6
|
|
General
(Configuration Change (Detection Logic))
|
A General detection named "Living Off The Land Binaries (LOLBAS)" was generated when cmd.exe executed smrs.exe.
[1]
|
|
|
Tactic
(Configuration Change (Detection Logic))
|
A Tactic detection named "Scripting (Process)" was generated when cmd.exe executed smrs.exe.
[1]
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "Command-Line Interface (Process)" was generated when cmd.exe executed smrs.exe.
[1]
|
|
5.A.6
|
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "Command-Line Interface (Process)" was generated when powershell.exe spawned cmd.exe.
[1]
|
|
|
General
(Configuration Change (Detection Logic))
|
A General detection named "Living Off The Land Binaries (LOLBAS)" was generated when powershell.exe spawned cmd.exe.
[1]
|
Tactic
(Configuration Change (Detection Logic))
|
A Tactic detection named "Scripting (Process)" was generated when powershell.exe spawned cmd.exe.
[1]
|
|
5.C.5
|
|
|
7.A.2
|
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "Command-Line Interface (Process)" was generated when tiny.exe spawned cmd.exe.
[1]
|
General
(Configuration Change (Detection Logic))
|
A General detection named "Living Off The Land Binaries (LOLBAS)" was generated when tiny.exe spawned cmd.exe.
[1]
|
|
|
Tactic
(Configuration Change (Detection Logic))
|
A Tactic detection named "Scripting (Process)" was generated when tiny.exe spawned cmd.exe.
[1]
|
|
13.A.2
|
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "Command-Line Interface (Process)" was generated when Adb156.exe spawned cmd.exe.
[1]
|
Tactic
(Configuration Change (Detection Logic))
|
A Tactic detection named "Scripting (Process)" was generated when Adb156.exe spawned cmd.exe.
[1]
|
General
(Configuration Change (Detection Logic))
|
A General detection named "Living Off The Land Binaries (LOLBAS)" was generated when Adb156.exe spawned cmd.exe.
[1]
|
|
|
|
13.B.2
|
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "Command-Line Interface (Process)" was generated when Adb156.exe spawned cmd.exe.
[1]
|
General
(Configuration Change (Detection Logic))
|
A General detection named "Living Off The Land Binaries (LOLBAS)" was generated when Adb156.exe spawned cmd.exe.
[1]
|
Tactic
(Configuration Change (Detection Logic))
|
A Tactic detection named "Scripting (Process)" was generated when Adb156.exe spawned cmd.exe.
[1]
|
|
|
|
14.A.1
|
|
General
(Configuration Change (Detection Logic))
|
A General detection named "Living Off The Land Binaries (LOLBAS)" was generated when Adb156.exe spawned cmd.exe.
[1]
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "Command-Line Interface (Process)" was generated when Adb156.exe spawned cmd.exe.
[1]
|
|
|
Tactic
(Configuration Change (Detection Logic))
|
A Tactic detection named "Scripting (Process)" was generated when Adb156.exe spawned cmd.exe.
[1]
|
|
16.A.3
|
|
Tactic
(Configuration Change (Detection Logic))
|
A Tactic detection named "Scripting (Process)" was generated when powershell.exe spawned cmd.exe.
[1]
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "Command-Line Interface (Process)" was generated when powershell.exe spawned cmd.exe.
[1]
|
|
|
General
(Configuration Change (Detection Logic))
|
A General detection named "Living Off The Land Binaries (LOLBAS)" was generated when powershell.exe spawned cmd.exe.
[1]
|
|
17.A.3
|
|
General
(Configuration Change (Detection Logic))
|
A General detection named "Living Off The Land Binaries (LOLBAS)" was generated when svchost.exe spawned cmd.exe.
[1]
|
|
A Technique detection named "Command-Line Interface (svchost.exe spawns cmd.exe)" was generated when svchost.exe spawned cmd.exe.
[1]
[2]
|
|
|
Tactic
(Configuration Change (Detection Logic))
|
A Tactic detection named "Scripting (Process)" was generated when svchost.exe spawned cmd.exe.
[1]
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "Command-Line Interface (Process)" was generated when svchost.exe spawned cmd.exe.
[1]
|
|