Analysis on legit tools abused in human-operated ransomware
SANS Ransomware Summit 2023
Analysis on legit tools abused in human-operated ransomware
Speakers:
Toru Yamashige, Senior Incident Response Consultant, Trend Micro Inc.
Keisuke Tanaka, Principal Incident Response Consultant, Trend Micro Inc.
As the detection logics of AV vendors improve, threat actors employ countermeasures to evade them. One of the most common ways in which threat actors hide from detection and carry out their malicious activities is by abusing legitimate tools. We believe that “legitimate tools“ can be classified into three categories below, with a marked increase in the number of cases in which “commercial tools“ are being abused: - MS native tools, such as PsExec, PowerShell, and WMI. - Legitimate penetration testing tools, including Cobalt Strike, Metasploit, and Mimikatz. - Commercial tools, such as Atera, AnyDesk, and Splashtop. Regarding MS native tools, techniques such as LOLBAS and LOLBIN are well-researched, while AV vendors are making efforts to detect penetration testing tools. We feel that threat actors are likely to abuse commercial tools these days as the tools are highly functional and commonly used in corporate operations. There is, however, little research on the exact functionalities of these tools, the traces they leave behind when abused, and countermeasures to prevent such abuse. Therefor, in this presentation, we will focus on actual incident cases where commercial tools were abused and try to explain the details based on the following three points: Chapter 1: Introducing actual incident response cases we have supported in which commercial tools were abused and describing their functionalities. Chapter 2: Explaining the traces and artifacts left behind when the tools are abused in an attack, so that the audience can use this information in their actual incident response investigations. Chapter 3: Describing effective countermeasures against attacks that exploit the tool, which will be useful for containment during incident response and for considerations during normal operations.
View upcoming Summits:
1 view
213
45
1 day ago 00:29:18 1
Смысл важнее крови: О чём эта война на самом деле — Щелин | Знай Правду
3 days ago 00:23:09 0
Катастрофа на фронте: что ждёт Украину — Арестович | Знай Правду
1 week ago 00:17:26 2
Russia’s Biggest Attack Ends in Collapse. Hundreds of Tanks Wiped Out in One Strike @UNITED24media
2 weeks ago 00:06:56 0
Is Aamir Khan’s Sitaare Zameen Par a Game Changer for Indian Cinema?
3 weeks ago 00:00:00 1
LIVE News: Victory Day 2025 Fireworks in Moscow | 80th Anniversary Celebration of WWII Victory
3 weeks ago 00:00:00 8
Russia Victory Day 2025 LIVE: Putin Leads Russia’s Largest Military Parade in Moscow | World News
4 weeks ago 00:09:47 2
Something BIG is happening in Europe, the power FAILURE is just phase one | Redacted News
1 month ago 00:21:36 4
IS THE TRAGIC ENDING OF VIRGINIA GIUFFRE A COVER UP? #royalfamily #meghanmarkle
1 month ago 00:25:07 1
“I do control that party“ Nigel Farage fury as Ben Habib launches Integrity Party to rival Reform UK
2 months ago 00:22:13 2
America NOT PREPARED: U.S. Military FEARS China’s Shocking New Power w/ Carl Zha & KJ Noh
2 months ago 00:00:00 1
Bucha Massacre Row At UN LIVE | Putin Aide ‘Proves’ How Kyiv & UK Conspired To Defame Russia
2 months ago 00:08:37 0
Trump has ’declared war on the rule of law’ in America: Fmr. Federal Judge J. Michael Luttig
2 months ago 00:08:04 0
‘Nail in the coffin for rural America’: Tester breaks down the devastating impact of Trump cuts
2 months ago 00:06:21 0
Узоры крючком. Японские кружочки - Japanese circles
3 months ago 01:32:16 10
The coming UK civil holy war
4 months ago 00:07:48 0
Fmr. Amb: Reported Trump Devil’s Bargain After Khashoggi Killing Horrendous | The Last Word | MSNBC
4 months ago 00:50:14 10
CHECKMATE: Russia-Iran Treaty SHOCKS The West | Dr. Pietro Shakarian
4 months ago 00:00:00 2
Trump LIVE: ’Grab Them...’: U.S. President Orders Migrant Detentions At Guantanamo; Cuba Attacks
4 months ago 00:00:00 0
LIVE | ’F**K Netanyahu’: Trump Shocks Israel Amid War | No Jan Oath Day Invite For Bibi?
4 months ago 00:00:00 0
LIVE | IDF’s Biggest Admission On Houthi Attacks: Yemen Rains 40 Ballistic Missiles On Israel
5 months ago 00:01:57 55
Trump Threatens Denmark With Tariffs Over Greenland
5 months ago 00:52:05 2
Russia Advancing on All Fronts: Toretsk Hangs by a Thread w/Patrick Henningsen
5 months ago 00:29:01 9
’GET OUT NOW’: California residents devastated by catastrophic wildfires
5 months ago 00:00:00 11
LIVE | Putin Kicks Off Orthodox Christmas Celebrations; Attends Mass In Moscow | Watch