Audit Policy Tampering Via Auditpol

 Original Source: [Sigma source]
Title: Audit Policy Tampering Via Auditpol
Status: test
Description:Threat actors can use auditpol binary to change audit policy configuration to impair detection capability. This can be carried out by selectively disabling/removing certain audit policies as well as restoring a custom policy owned by the threat actor.
References:
  -https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/
Author: Janantha Marasinghe (https://github.com/blueteam0ps)
Date: 2021-02-02
modified:2023-02-22
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\auditpol.exe' OriginalFileName:'AUDITPOL.EXE'   selection_cli:
    CommandLine|contains:
      -'disable'
      -'clear'
      -'remove'
      -'restore'

  condition:all of selection_*
Falsepositives:
  -Administrator or administrator scripts might leverage the flags mentioned in the detection section. Either way, it should always be monitored
Level: high