Title:
Tamper With Sophos AV Registry Keys
Status:
test
Description:Detects tamper attempts to sophos av functionality via registry key modification
References:
-https://redacted.com/blog/bianlian-ransomware-gang-gives-it-a-go/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-09-02
modified:2023-08-17
Tags:
- -'attack.defense-impairment'
- -'attack.t1685'
Logsource:
- category: registry_set
- product: windows
Detection:
selection:
TargetObject|contains:
-'\Sophos Endpoint Defense\TamperProtection\Config\SAVEnabled'
-'\Sophos Endpoint Defense\TamperProtection\Config\SEDEnabled'
-'\Sophos\SAVService\TamperProtection\Enabled'
Details:
'DWORD (0x00000000)'
condition:
selection
Falsepositives:
-Some FP may occur when the feature is disabled by the AV itself, you should always investigate if the action was legitimate
Level:
high