part 2
some of SOPs
π¨ Signed Binary Proxy Execution - mshta.exe
mshta.exeπ 1. Attack Breakdown
π What is mshta.exe?
mshta.exe?π Why Attackers Abuse mshta.exe?
mshta.exe?π Common Malicious Uses of mshta.exe
mshta.exeπ‘οΈ 2. Detection Techniques
π Manual Inspection
π Microsoft Defender for Endpoint (MDE) Query (KQL)
π Event Viewer Logs
π΅οΈ 3. Investigation Techniques
1οΈβ£ Inspect Command Line Arguments
2οΈβ£ Check Remote Connections
3οΈβ£ Validate Remote URLs or IPs
4οΈβ£ Inspect Registry Persistence
5οΈβ£ Analyze HTA Files
π§ 4. Remediation Steps
π 1. Terminate Suspicious Processes
π 2. Block Outbound Traffic
π 3. Remove Registry Persistence
π 4. Quarantine Malicious Files
π 5. Perform Full Antivirus Scan
π‘οΈ 5. Prevention Steps
π§ 6. Key Takeaways
π¨ Signed Binary Proxy Execution - regsvr32.exe
regsvr32.exeπ 1. Attack Breakdown
π What is regsvr32.exe?
regsvr32.exe?π Why Attackers Abuse regsvr32.exe?
regsvr32.exe?π Common Malicious Uses of regsvr32.exe
regsvr32.exeπ‘οΈ 2. Detection Techniques
π Manual Inspection
π Microsoft Defender for Endpoint (MDE) Query (KQL)
π Event Viewer Logs
π΅οΈ 3. Investigation Techniques
1οΈβ£ Inspect Command Line Arguments
2οΈβ£ Validate Remote URLs or IPs
3οΈβ£ Trace Parent Processes
4οΈβ£ Analyze Network Traffic
5οΈβ£ Inspect Registry for Persistence
π§ 4. Remediation Steps
π 1. Terminate Suspicious Processes
π 2. Block Outbound Traffic
π 3. Remove Registry Persistence
π 4. Quarantine Malicious Files
π 5. Perform Full Antivirus Scan
π‘οΈ 5. Prevention Steps
π§ 6. Key Takeaways
π¨ Signed Binary Proxy Execution - rundll32.exe
rundll32.exeπ 1. Attack Breakdown
π What is rundll32.exe?
rundll32.exe?π Why Attackers Abuse rundll32.exe?
rundll32.exe?π Common Malicious Uses of rundll32.exe
rundll32.exeπ‘οΈ 2. Detection Techniques
π Manual Inspection
π Microsoft Defender for Endpoint (MDE) Query (KQL)
π Event Viewer Logs
π΅οΈ 3. Investigation Techniques
1οΈβ£ Inspect Command Line Arguments
2οΈβ£ Trace Parent Processes
3οΈβ£ Validate Remote IPs/URLs
4οΈβ£ Analyze DLLs
5οΈβ£ Check Registry for Persistence
π§ 4. Remediation Steps
π 1. Terminate Suspicious Processes
π 2. Block Outbound Traffic
π 3. Remove Registry Persistence
π 4. Quarantine Suspicious DLLs
π 5. Perform Full Antivirus Scan
π‘οΈ 5. Prevention Steps
π§ 6. Key Takeaways
π¨ Kerberoasting Attack: Advanced Threat Analysis
π 1. Attack Breakdown
π What is Kerberoasting?
π Why Attackers Use Kerberoasting?
π Attack Phases
π Tools Commonly Used in Kerberoasting
π‘οΈ 2. Detection Techniques
π Manual Detection with PowerShell
π Microsoft Defender for Endpoint (MDE) Query (KQL)
π Event Viewer Logs
π΅οΈ 3. Investigation Techniques
1οΈβ£ Identify Target Accounts
2οΈβ£ Trace IP Address of Ticket Requests
3οΈβ£ Analyze Tools Used
4οΈβ£ Check Offline Password Cracking Activity
5οΈβ£ Investigate Credential Use Post-Cracking
π§ 4. Remediation Steps
π 1. Reset Compromised Account Passwords
π 2. Enable Kerberos AES Encryption
π 3. Audit Service Accounts
π 4. Monitor for Tools and Scripts
π 5. Enable Account Lockout Policy
π‘οΈ 5. Prevention Steps
π§ 6. Key Takeaways
π¨ Golden Ticket Attack: Advanced Threat Analysis
π 1. Attack Breakdown
π What is a Golden Ticket Attack?
π Why Attackers Use Golden Tickets?
π‘οΈ Requirements for a Golden Ticket Attack:
π Attack Steps:
π Common Tools Used in Golden Ticket Attacks
π‘οΈ 2. Detection Techniques
π Manual Detection with PowerShell
π Microsoft Defender for Endpoint (MDE) Query (KQL)
π Event Viewer Logs
π΅οΈ 3. Investigation Techniques
1οΈβ£ Inspect KRBTGT Account Activity
2οΈβ£ Trace Kerberos Tickets
3οΈβ£ Analyze Ticket Requests
4οΈβ£ Monitor High-Privilege Accounts
5οΈβ£ Identify Tool Artifacts
π§ 4. Remediation Steps
π 1. Reset the KRBTGT Account Twice
π 2. Revoke Active Kerberos Tickets
π 3. Remove Malicious Tickets
π 4. Audit Domain Admin Accounts
π 5. Update and Patch Systems
π 6. Conduct Full Antivirus Scan
π‘οΈ 5. Prevention Steps
π§ 6. Key Takeaways
π¨ Silver Ticket Attack
π 1. Attack Breakdown
π What is a Silver Ticket Attack?
π Why Attackers Use Silver Tickets?
π Attack Steps:
π Common Tools for Silver Ticket Attacks
π‘οΈ 2. Detection Techniques
π Manual Detection with PowerShell
π Microsoft Defender for Endpoint (MDE) Query (KQL)
π Event Viewer Logs
π΅οΈ 3. Investigation Techniques
1οΈβ£ Validate TGS Ticket Requests
2οΈβ£ Identify Hash Dumping Activities
3οΈβ£ Trace Service Account Usage
4οΈβ£ Analyze Service Ticket Lifetimes
5οΈβ£ Validate Source IP Addresses
π§ 4. Remediation Steps
π 1. Reset Service Account Passwords
π 2. Revoke Compromised Tickets
π 3. Monitor Service Accounts
π 4. Rotate Service Account Passwords Periodically
π 5. Terminate Malicious Processes
π 6. Perform Full Antivirus Scan
π‘οΈ 5. Prevention Steps
π§ 6. Key Takeaways
Last updated