Carbanak+FIN7
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
5.C.2
|
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "SMB/Windows Admin Shares - T1021.002" (High) was generated when psexec.py connected to SMB shares on 10.0.0.4.
[1]
|
|
|
|
16.A.5
|
|
|
|
|
A Technique detection named "SMB/Windows Admin Share" was generated when paexec.exe created an SMB session from 10.0.1.5 to 10.0.1.6 and created a file on the remote admin share.
[1]
|
|
psexec.py connects to SMB shares on 10.0.0.4
-
Detection and tagging logic
[1]
psexec.py connects to SMB shares on 10.0.0.4
[1]
SMB session from 10.0.1.5 to 10.0.1.6 over TCP port 135 or 445 with admin shares accessed
-
Windows Event Logs
-
Process Monitoring
[1]
[2]
SMB session from 10.0.1.5 to 10.0.1.6 over TCP port 135 or 445 with admin shares accessed
[1]