Windows CrowdStrike Agent Registry Key Removal: endpointEndpointNoneversion:2
Detects delete events on the CrowdStrike registry keys.
These keys are removed as part of the agent uninstallation process.
This activity should only occur during planned events and any instances outside that should be evaluated for malicious activity such as CVE-2022-44721.
Windows Filtering Platform Policy Added to Block EDR Process: endpointEndpointNoneversion:2
Detects the modification of a Windows Filtering Platform Policy to block the communication of known EDR processes.
This can be used by attackers to impair the functionality of these tools and to hide their activities on the machine.
Windows Cisco Secure Endpoint Stop Immunet Service Via Sfc: endpointEndpointNoneversion:7
The following analytic detects the use of the `sfc.exe` utility, in order to stop the Immunet Protect service. The Sfc.exe utility is part of Cisco Secure Endpoint installation. This detection leverages telemetry from the endpoint, focusing on command-line executions involving the `-k` parameter. This activity is significant as it indicates potential tampering with defensive mechanisms. If confirmed malicious, attackers could partially blind the EDR, enabling further compromise and lateral movement within the network.
Windows EDRSilencer Custom Outbound Filter Added: endpointEndpointNoneversion:1
The following analytic detects the EDRSilencer-specific Windows Filtering Platform filter name "Custom Outbound Filter" when it is configured with a block action.
EDRSilencer creates WFP filters to block outbound traffic from EDR and security agent processes, impairing endpoint telemetry without requiring the tool binary to keep its original process name.
EventCode 5447 identifies creation of the runtime filter with ChangeType %%16384, while EventCode 5441 can show the same persistent filter when the Base Filtering Engine starts.
Windows Filtering Platform Filter Added To Block EDR Process: endpointEndpointNoneversion:1
The following analytic detects Windows Filtering Platform filters that are added and configured to block outbound traffic for known EDR and security agent processes.
Tools such as EDRSilencer abuse WFP to disrupt outbound telemetry from EDR processes, which can bypass detections that only look for the tool process name.
This detection looks for WFP add events with a block action and EDR process names embedded in the hexdump-like Conditions field.
Windows Cisco Secure Endpoint Unblock File Via Sfc: endpointEndpointNoneversion:7
The following analytic detects the use of the sfc.exe utility with the "-unblock" parameter, a feature within Cisco Secure Endpoint. The "-unblock" flag is used to remove system blocks imposed by the endpoint protection. This detection focuses on command-line activity that includes the "-unblock" parameter, as it may indicate an attempt to restore access to files or processes previously blocked by the security software. While this action could be legitimate in troubleshooting scenarios, malicious actors might use it to override protective measures, enabling execution of blocked malicious payloads or bypassing other security mechanisms.
Windows EDRSilencer Execution: endpointEndpointNoneversion:3
Detects the usage of EDRSilencer.
Inspired by the closed-source FireBlock tool from MdSec NightHawk, this custom tool was developed to block outbound traffic of running Endpoint Detection and Response (EDR) processes using Windows Filtering Platform (WFP) APIs.
Its features include searching for running EDR processes and applying WFP filters to block outbound traffic, adding filters for specific processes, and removing filters either individually or globally.
The tool includes a custom implementation to avoid file handle access issues with EDR processes by bypassing the CreateFileW API.
It supports a wide range of EDRs, including Microsoft Defender, Carbon Black, SentinelOne, and more, though further testing on various EDRs is recommended.
The tool has been tested on Windows 10 and Windows Server 2016, and its usage involves simple commands for blocking or unblocking traffic.
Windows Cisco Secure Endpoint Uninstall Immunet Service Via Sfc: endpointEndpointNoneversion:7
The following analytic detects the use of the sfc.exe utility with the "-u" parameter, which is part of the Cisco Secure Endpoint installation. The "-u" flag allows the uninstallation of Cisco Secure Endpoint components. This detection leverages endpoint telemetry to monitor command-line executions that include the "-u" parameter. The use of this flag is significant as it could indicate an attempt to disable or remove endpoint protection, potentially leaving the system vulnerable to further exploitation. If identified as malicious, this action may be part of a broader effort to disable security mechanisms and avoid detection.
Windows Cisco Secure Endpoint Related Service Stopped: endpointEndpointNoneversion:7
The following analytic detects the suspicious termination of known services commonly targeted by ransomware before file encryption. It leverages Windows System Event Logs (EventCode 7036) to identify when critical services such as Volume Shadow Copy, backup, and antivirus services are stopped. This activity is significant because ransomware often disables these services to avoid errors and ensure successful file encryption. If confirmed malicious, this behavior could lead to widespread data encryption, rendering files inaccessible and potentially causing significant operational disruption and data loss.