8 hours 28 minutes
hello and welcome to another application of the minor attack framework discussion. Today, we're going to be looking at persistence mechanism known as new service. So with that, let's go ahead and jump into our objectives.
So the objectives up today's discussion are to describe what new service is with respect to the framework.
How has new service been used? Some mitigation techniques and some detection techniques.
So new service is when a threat actor or actors take advantage of systems by installing a new service that can be configured to execute it. Startup. Using utilities to interact with the service or by modifying the registry.
So threat actors will typically name services after legit software to attempt to circumvent controls or bypass detection methods. Services are commonly used to perform privilege escalation to get an administrator account to system level again.
Sometimes US services run at system level, and you can go in and do a quick control ult elite. And so, while we're sitting here,
I can actually go ahead and demonstrate that
so I hit control delete.
Click outside of that
and then if we go into task manager and we actually look at some of the services here.
A threat actor could potentially attempt to run as any given service in these areas. And so it's got groups and things of that nature and like a local service. And if we go into the details and look here, we'll actually see that a number of services are running a system
and things of that nature. And so
if a threat actor is able to take ah particular service and run as that service, like, inject itself into that, uh, and take over that particular P I D or something of that nature, they could potentially have system level privilege. And so
this particular type of attack could be very beneficial for a threat actor if they're able to get system level
access. So let's talk about the Trojan Rocky Manu eso Ricky Manu is a Trojan that stills information from the compromised system. And so, just to give you an idea of how this works, it creates be following files. So in the help
C n d y dot dat, and then it does I r m o n dot de l. L.
And so then it. After creating these two areas here, will create the following service I arm on, which is the name of the service. It will have an image path as follows here
and then the description. It will actually have a written out description. And so it indicates here that infrared port monitor is present for all computers with infrared ports. It initiates file transfers between your computer and another device, like a PD A or mobile phone.
So very interesting. So if we're not savvy, if we're not really paying attention,
if we don't know what we're looking for, this could potentially sneak under the radar as far as having that installed on us, never knowing the difference.
So let's go ahead and look at some mitigation techniques for this as well. So limit user account privileges to those necessary and do not allow accounts to have administrative access again for daily tasks. Utilize malware detection and prevention tools to slow down or stop known variants of these types of attacks.
Again, there may be components of these packages that could be undetected if even if the animals were able to get, it may be providing a false sense of security,
and again we keep coming back to not allowing administrative access for daily tasks. I know that that's becoming redundant, but it is a mitigating technique for several of these areas within persistence.
Now let's talk about some detection techniques at a high level. We can monitor service creation and changes in the registry. And so we shouldn't be making daily changes to our registry. Eso. Anytime changes occurred, we would want to alert on that and evaluated to see if it was legitimate. Activity.
Analysis should be done on multiple events to determine if a threat actor is potentially in the network. And so what this means
is you don't want to do a one for 11 thing happens, we review it. One thing happens. We look at it. We want to take a group of events, cluster those together and see if those activities correlate with things that a threat actor would be doing. A network scan in map scans
attempts to load software's attempts to do privilege escalation. All of that may be
ties back. Teoh known bad I P addresses that something tried to reach out to
again. So you can't take, you know, a single event and tie it back to a threat actor. In most cases, you'll have to take multiple events, put them all together and kind of create a chain of attacks that this threat actor was moving through.
And so look for changes in systems that do not correlate with patching or other system management practices. So if there was no patching going on that day, if we weren't supposed to be making changes, if there was nothing on the calendar for us to be doing,
why did it happen? And if something is different, or if something's out of place, then it makes sense to evaluate it and see if you can tie it back to either legitimate function or business function or if it is indeed a threat actor.
Now, let's do a quick check on learning. Implementing a new service does not allow threat actors to get system level access.
All right, well, if you need additional time to evaluate the statement, please do so. So the key thing here is is that implementing a new service okay does not allow the threat actor to gain system level access. When we just did a quick look at the command prompt are the
task manager and we found that there were a number of services running at system
a false statement. A threat actor could be allowed
okay to get system level access by implementing a new service, depending on what they do. So with that, let's go ahead and jump over to our summary. So we described what new services and essentially, this is where a threat actor either injects themselves into a current service or creates a new service on a system.
We review how the new service has been used or how it could be used by evaluating a particular Trojan and some things that it does to the system.
We reviewed some mitigation techniques, and we looked at some detection techniques. So as well. Again, we will continue to generate any time. It is pertinent that administrative access in limited quantities is good. Least privilege is good. Ah, high number of these attack vectors are mitigated by things that weaken dio
with little to no cost to our organizations.
So with that in mind, I want to thank you for your time today, and I look forward to seeing you again soon.
MITRE ATT&CK Defender™ (MAD) ATT&CK® SOC Assessments Certification Training
This course prepares you for the ATT&CK® Security Operations Center Certification. In this course, students ...
2 CEU/CPE Hours Available
Certificate of Completion Offered
MITRE ATT&CK Defender™ (MAD) ATT&CK® Fundamentals Badge Training
This course is the fundamental piece of the MITRE ATT&CK Defender™ (MAD) series where we ...
2 CEU/CPE Hours Available
Certificate of Completion Offered