LoFP LoFP / false positives will be present and filtering will be required. legitimate ips will be present and need to be filtered.

Techniques

Sample rules

Windows WinLogon with Public Network Connection

Description

The following analytic detects instances of Winlogon.exe, a critical Windows process, connecting to public IP addresses. This behavior is identified using Endpoint Detection and Response (EDR) telemetry, focusing on network connections made by Winlogon.exe. Under normal circumstances, Winlogon.exe should not connect to public IPs, and such activity may indicate a compromise, such as the BlackLotus bootkit attack. This detection is significant as it highlights potential system integrity breaches. If confirmed malicious, attackers could maintain persistence, bypass security measures, and compromise the system at a fundamental level.

Detection logic


| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes
  WHERE Processes.process_name IN (winlogon.exe) Processes.process!=unknown
  BY Processes.action Processes.dest Processes.original_file_name
     Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid
     Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path
     Processes.process Processes.process_exec Processes.process_guid
     Processes.process_hash Processes.process_id Processes.process_integrity_level
     Processes.process_name Processes.process_path Processes.user
     Processes.user_id Processes.vendor_product

| `drop_dm_object_name(Processes)`

| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| join process_id [

| tstats `security_content_summariesonly` count FROM datamodel=Network_Traffic.All_Traffic
  WHERE All_Traffic.dest_port != 0 NOT (All_Traffic.dest IN (127.0.0.1,10.0.0.0/8,172.16.0.0/12, 192.168.0.0/16, 0:0:0:0:0:0:0:1))
  BY All_Traffic.process_id All_Traffic.dest All_Traffic.dest_port

| `drop_dm_object_name(All_Traffic)`

| rename dest as publicIp ]

| table dest parent_process_name process_name process_path process process_id dest_port publicIp

| `windows_winlogon_with_public_network_connection_filter`