Title:
Audit Policy Tampering Via Auditpol
Status:
test
Description:Threat actors can use auditpol binary to change audit policy configuration to impair detection capability.
This can be carried out by selectively disabling/removing certain audit policies as well as restoring a custom policy owned by the threat actor.
References:
-https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/
Author: Janantha Marasinghe (https://github.com/blueteam0ps)
Date: 2021-02-02
modified:2023-02-22
Tags:
- -'attack.defense-impairment'
- -'attack.t1685.001'
Logsource:
- category: process_creation
- product: windows
Detection:
selection_img:
Image|endswith:
'\auditpol.exe'
OriginalFileName:
'AUDITPOL.EXE'
selection_cli:
CommandLine|contains:
-'disable'
-'clear'
-'remove'
-'restore'
condition:
all of selection_*
Falsepositives:
-Administrator or administrator scripts might leverage the flags mentioned in the detection section. Either way, it should always be monitored
Level:
high