LoFP LoFP / remediation of various container files, such as archives, might also lead to creation various defender artifacts smartscreen interferes with the remediation process, potentially causing additional defender artifacts to be created.

Techniques

Sample rules

Windows Defender Intermediary Artifact Was Observed

Description

The following analytic detects creation and removal of intermediary remediation artifacts of Windows Defender, during exploitation of ShieldCrash attacks. Exploit abuses the race condition between file validation and its remediation performed by Windows Defender. In between these steps, ShieldCrash changes the symbolic link to redirect the remediation process to a staging directory controlled by the attacker. This detection aims to detect creation of defender artifact, its alternate data stream, and their subsequent removal.

Detection logic

`sysmon`
EventID IN (11, 15, 23)
process_name IN (
    "System",
    "msmpeng.exe"
)
user=SYSTEM
NOT TargetFilename IN (
    "C:\\Windows\\Temp\\*",
    "*:Zone.Identifier",
    "*:SmartScreen"
)


| regex TargetFilename!="(?i)\.\w{1,10}$"


| stats count values(EventID) as EventID
              values(TargetFilename) as TargetFilename
              dc(EventID) as dc_EventID
              dc(TargetFilename) as dc_TargetFilename
              min(_time) as firstTime
              max(_time) as lastTime

  by dest process_id process_name user


| search dc_TargetFilename>1 dc_EventID>1


| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `windows_defender_intermediary_artifact_was_observed_filter`