<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Netwitness Security LLC blog</title>
    <link>https://mydev.netwitness.com/netwitness-security-llc-blog</link>
    <description />
    <language>en</language>
    <pubDate>Thu, 18 Jun 2026 14:37:48 GMT</pubDate>
    <dc:date>2026-06-18T14:37:48Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Netwitness Platform Integration with AWS Application Load Balancer Access logs</title>
      <link>https://mydev.netwitness.com/netwitness-security-llc-blog/netwitnessplatformintegrationwithawsapplicationloadbalanceraccesslogs</link>
      <description>&lt;p&gt;&lt;strong&gt;Load balancers&lt;/strong&gt; sit Infront of the servers, distributes and balances the network and application traffic among many servers. Usually, the load balancer helps to increase the availability and redirect the requests across a few servers managing the load on each server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Load balancers&lt;/strong&gt; sit Infront of the servers, distributes and balances the network and application traffic among many servers. Usually, the load balancer helps to increase the availability and redirect the requests across a few servers managing the load on each server.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;AWS Application Load balancer&lt;/strong&gt; balances HTTP and HTTPS traffic from clients to the target EC2 instance or container or the lambda function across different availability zones. ALB listeners checks the client requests based on the rules configured and target group routes the request to one of the registered target.&lt;/p&gt; 
&lt;p&gt;Netwitness Integrates the AWS Application load balancer &lt;strong&gt;access log&lt;/strong&gt; via &lt;strong&gt;s3universal plugin&lt;/strong&gt;.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Integration Model:&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/424958i235D097BE0DDE2C8.png?width=783&amp;amp;height=538&amp;amp;name=424958i235D097BE0DDE2C8.png" width="783" height="538" title="RachanaSR_0-1683643502885.png" alt="RachanaSR_0-1683643502885.png"&gt;&lt;/p&gt; 
&lt;p&gt;To take advantage of this new capability within RSA NetWitness, please visit the link below and search for the terms below in RSA Live.&lt;br&gt;&lt;strong&gt;Configuration Guide:&amp;nbsp;&lt;a href="https://community.netwitness.com/s/article/S3UniversalConnectorEventSourceLogConfigurationGuide"&gt;Amazon S3 Universal Connector&lt;/a&gt;&amp;nbsp;&lt;/strong&gt;&lt;br&gt;&lt;strong&gt;Collector Package on RSA Live:&lt;/strong&gt;&amp;nbsp;"Log Collector configuration content for event source AWS S3"&lt;br&gt;&lt;strong&gt;Parser on RSA Live&lt;/strong&gt;: aws&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50269063&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmydev.netwitness.com%2Fnetwitness-security-llc-blog%2Fnetwitnessplatformintegrationwithawsapplicationloadbalanceraccesslogs&amp;amp;bu=https%253A%252F%252Fmydev.netwitness.com%252Fnetwitness-security-llc-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 23 Jul 2024 04:00:00 GMT</pubDate>
      <guid>https://mydev.netwitness.com/netwitness-security-llc-blog/netwitnessplatformintegrationwithawsapplicationloadbalanceraccesslogs</guid>
      <dc:date>2024-07-23T04:00:00Z</dc:date>
      <dc:creator>RachanaSR</dc:creator>
    </item>
    <item>
      <title>The Sky Is Crying: The Wake of the 19 JUL 2024 CrowdStrike Content Update for Microsoft Windows and We Should Take Away From It</title>
      <link>https://mydev.netwitness.com/netwitness-security-llc-blog/715124</link>
      <description>&lt;p&gt;&lt;strong&gt;Introduction&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Introduction&amp;nbsp;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Yesterday was a challenging day for many organizations, teams, and individuals worldwide. We can all agree that it was stressful, and the impacts are still being assessed. It will take some time for many organizations to fully understand the ramifications of what has been called the single-largest IT outage in history&lt;a href="#_edn1"&gt;[i]&lt;/a&gt;. On a personal note, my own family was impacted, which brought the matter home for me and many others. The outage resulted from a content update pushed by CrowdStrike to its global customer base. The systems impacted by this content update were those running the Microsoft Windows operating system. The organization has acknowledged that neither Apple Mac nor Linux hosts were affected, and this was not the result of a cyberattack – a fact that led many to feel relieved, albeit for a brief time.&amp;nbsp;Industry veteran and CrowdStrike CEO, George Kurtz, stated on the official CrowdStrike blog and through the media&lt;a href="#_edn2"&gt;[ii]&lt;/a&gt; that, "The issue has been identified, isolated, and a fix has been deployed."&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What We Should Focus on and Take Away from This Event&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;In my opinion, what we as an industry and organization should focus on as a result of this unfortunate situation boils down to the following:&amp;nbsp;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Producing high-quality and consistent code – in addition to the products that leverage said code is difficult and warrants an unrelenting commitment to quality, process, procedure, and thoroughness (see SDLC+Security, The Rugged Software Movement, and many other sources on this topic). CrowdStrike and in this case Microsoft, are no strangers to producing high-quality, effective, and globally adopted and trusted products and my belief is this unfortunate event will further strengthen their resolve to delivering high-quality, and performant technology as they move on from this over time.&amp;nbsp;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt;Resilience and fault tolerance in application, small systems, and Internetworking Infrastructure should be factored into design by vendors and consumers alike as we place high degrees of trust in these things on the vendor/provider side of the equation and the consumer (in this case business consumers and beyond). Looking at this from an IT/Internetworking perspective it is clear to me that though there is merit in the cloud and its use as an infrastructure option and alternative, it is just one such construct and should be scrutinized and reconsidered as the net effect observed in this incident was exacerbated by the use of cloud and its impact on systems in cloud and on premises, the latter of which required a significant amount of human intervention.&amp;nbsp;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt;Resilience and fault tolerance in design influence and underscore confidence in business continuity planning and disaster recovery (BCP/DR). Historically, BCP/DR has been looked at as an adjunct element of cybersecurity (see the CIA model and domains associated with the ISC2 CISSP for more detail among many other sources). The reality is that a lapse in BCP/DR and subsequent availability can and may have an impact (time will tell and this will remain to be seen) risk posture and attack surface exposure and management, respectively.&amp;nbsp;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt;Defense in depth is still – despite many novel and noteworthy attempts by marketing teams through the years to message to the contrary, a terribly important aspect of building solid security programs, managing those programs, in addition to designing, architecting, and managing highly secure networks that continue to deliver visibility, and cognizance of the state of the network (and those assets associated and attached to it). Thus, the risk posture and attack surface become defendable even in the wake of something being unavailable, evaded, or failing.&amp;nbsp;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;At NetWitness, many of us are personal friends and colleagues with individuals and teams at both CrowdStrike and Microsoft. Additionally, we are proud to share many joint customers with both organizations and will continue to do our best to be good stewards of those relationships while maintaining a dedicated stance in providing the highest quality products, services, and guidance we can to those customers, in addition to organizations that we are not yet operating within today. If you or your organization have been impacted by the events associated with this recent content push by CrowdStrike and would like to speak to anyone here at NetWitness in regard to what you can do beyond the measures laid out by CrowdStrike to date to ensure your organization has the most optimal and comprehensive visibility and network detection and response at your disposal, please do not hesitate to contact us.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&lt;a href="#_ednref1"&gt;[i]&lt;/a&gt; &lt;a href="https://www.cnbc.com/2024/07/19/latest-live-updates-on-a-major-it-outage-spreading-worldwide.html"&gt;https://www.cnbc.com/2024/07/19/latest-live-updates-on-a-major-it-outage-spreading-worldwide.html&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;[i] &lt;a href="https://www.tomsguide.com/news/live/microsoft-worldwide-outage-live"&gt;https://www.tomsguide.com/news/live/microsoft-worldwide-outage-live&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;[i] &lt;a href="https://www.yahoo.com/news/microsoft-outage-live-crowdstrike-boss-170429333.html"&gt;https://www.yahoo.com/news/microsoft-outage-live-crowdstrike-boss-170429333.html&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;&lt;a href="#_ednref2"&gt;[ii]&lt;/a&gt; &lt;a href="https://www.crowdstrike.com/blog/our-statement-on-todays-outage/"&gt;https://www.crowdstrike.com/blog/our-statement-on-todays-outage/&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;[ii] &lt;a href="https://x.com/george_kurtz/status/1814235001745027317?s=46"&gt;https://x.com/george_kurtz/status/1814235001745027317?s=46&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;[ii] &lt;a href="https://www.crowdstrike.com/blog/statement-on-falcon-content-update-for-windows-hosts/"&gt;https://www.crowdstrike.com/blog/statement-on-falcon-content-update-for-windows-hosts/&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50269063&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmydev.netwitness.com%2Fnetwitness-security-llc-blog%2F715124&amp;amp;bu=https%253A%252F%252Fmydev.netwitness.com%252Fnetwitness-security-llc-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Sat, 20 Jul 2024 04:00:00 GMT</pubDate>
      <guid>https://mydev.netwitness.com/netwitness-security-llc-blog/715124</guid>
      <dc:date>2024-07-20T04:00:00Z</dc:date>
      <dc:creator>Will_G</dc:creator>
    </item>
    <item>
      <title>DDoS using BotNet Use Case</title>
      <link>https://mydev.netwitness.com/netwitness-security-llc-blog/ddosusingbotnetusecase</link>
      <description>&lt;h2&gt;&lt;strong&gt;Introduction&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The NetBot tool is a versatile command and control center (CCC) for DDoS Botnet Attack Simulation &amp;amp; Load Generation, created by that is publicly available via GitHub (&lt;a href="https://github.com/skavngr/netbot"&gt;https://github.com/skavngr/netbot&lt;/a&gt;). This tool is a prototype that uses Python 3 to configure bots, set a CCC server for the bots to be connected to, as well as loading target information for the server.&lt;/p&gt;</description>
      <content:encoded>&lt;h2&gt;&lt;strong&gt;Introduction&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The NetBot tool is a versatile command and control center (CCC) for DDoS Botnet Attack Simulation &amp;amp; Load Generation, created by that is publicly available via GitHub (&lt;a href="https://github.com/skavngr/netbot"&gt;https://github.com/skavngr/netbot&lt;/a&gt;). This tool is a prototype that uses Python 3 to configure bots, set a CCC server for the bots to be connected to, as well as loading target information for the server.&lt;/p&gt; 
&lt;p&gt;As this tool is a prototype, it is made to simulate a Client-Server botnet environment using Proof-of-Concept (PoC) code to demonstrate security flaws in software or during a PoC exploit. It is also assists in simulating DDoS attacks towards the target to understand how DDoS attacks disrupts traffic of servers, services, and networks. The tool is straightforward and easy to grasp, making it accessible for users of all levels.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;NetBot CLI Banner&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428404i9C30F3690FD3696F.png?width=575&amp;amp;height=92&amp;amp;name=428404i9C30F3690FD3696F.png" width="575" height="92" title="Val04_0-1707974897348.png" alt="Val04_0-1707974897348.png"&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;Botnet&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;Botnet is a group of bots and devices (known as zombie bots) linked together to perform the same task, for distribution and scaling. Botnet attacks are used by cybercriminals to carry out intense scraping, DDoS, and other large-scale cybercrime. (MITRE Framework, Resource Development — Compromise Infrastructure: Botnet &lt;a href="https://attack.mitre.org/techniques/T1584/005/"&gt;https://attack.mitre.org/techniques/T1584/005/&lt;/a&gt;)&lt;/p&gt; 
&lt;p&gt;Botnet attacks are far more dangerous than single malware attacks because rather than infecting a single device, botnets infect hundreds, thousands, or even millions of connected devices at once. This poses an exponential threat that is much harder to stop. Making them even more evasive is the fact that the attacker can use incoming software updates from infected devices to redirect or scale up their attack on the fly. This helps attackers stay ahead of countermeasures employed by their victims. Armed with a large force of zombie bots, a single attacker can do more than compromise whole networks. They can quickly replicate and distribute their malware, hijacking growing numbers of devices.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Botnet Attack Diagram&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428405i8162091985897F57.png?width=763&amp;amp;height=264&amp;amp;name=428405i8162091985897F57.png" width="763" height="264" title="Val04_1-1707974897350.png" alt="Val04_1-1707974897350.png"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&lt;em&gt;What is a Botnet (IoT Botnet)? (&lt;/em&gt;&lt;/strong&gt;&lt;strong&gt;&lt;a href="https://www.a10networks.com/glossary/what-is-a-botnet-iot-botnet/"&gt;https://www.a10networks.com/glossary/what-is-a-botnet-iot-botnet/&lt;/a&gt;.)&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;‌&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;Attack Walkthrough&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;We will start with a nmap scan on the network to find for an open port.&amp;nbsp;The intent is to do a HTTP flood to the server by sending a lot of request packets to the HTTP website.&lt;/p&gt; 
&lt;p&gt;Take note, for this example, we hosted the webserver on port 8080 and will use port 8080.&amp;nbsp; In normal circumstances, the port we want to monitor is HTTP or HTTPS.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;nmap scan command&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428406iCA2934DF6E24AFCC.png?width=459&amp;amp;height=43&amp;amp;name=428406iCA2934DF6E24AFCC.png" width="459" height="43" title="Val04_2-1707974897352.png" alt="Val04_2-1707974897352.png"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;nmap scan results&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428407i05D041AF3AEA27DA.png?width=474&amp;amp;height=109&amp;amp;name=428407i05D041AF3AEA27DA.png" width="474" height="109" title="Val04_3-1707974897353.png" alt="Val04_3-1707974897353.png"&gt;&lt;/p&gt; 
&lt;p&gt;Once the target has been found, we make sure that we have access to the HTTP website using the IP address found and port.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Accessing the Website&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428409i4F6B2331701BF56F.png?width=656&amp;amp;height=323&amp;amp;name=428409i4F6B2331701BF56F.png" width="656" height="323" title="Val04_4-1707974897365.png" alt="Val04_4-1707974897365.png"&gt;&lt;/p&gt; 
&lt;p&gt;Next, we will check the response time of the server, record down on how fast the HTTP server will respond normally to requests when accessing the HTTP website. Use the root account and use the command to extract out the response time of the server.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;for (( ; ; )); do&lt;/strong&gt; - initiates a forever loop&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;curl -o /dev/null -s -w 'Response from Victim Server: %{time_total} seconds\n' &lt;a href="http://192.168.1.45:8080"&gt;http://192.168.1.45:8080&lt;/a&gt; &lt;/strong&gt;- send an HTTP request to a designated server, directing the output to /dev/null, muting the progress meter, and customizing the output format to display the total time taken for the request in seconds.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;sleep 1&lt;/strong&gt; - after each request, the script pauses for 1 second before sending the next request.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;done&lt;/strong&gt; - marks the end of the loop&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Retrieving Server Response Time&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428408i0AFF122EE3638A86.png?width=764&amp;amp;height=251&amp;amp;name=428408i0AFF122EE3638A86.png" width="764" height="251" title="Val04_5-1707974897369.png" alt="Val04_5-1707974897369.png"&gt;&lt;/p&gt; 
&lt;p&gt;From the target machine, the current CPU is running at around 27% which is a normal rate when running processes, apps, and tasks in the background.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;CPU Percentage in Task Manager&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428411i8854683CB87D4735.png?width=501&amp;amp;height=442&amp;amp;name=428411i8854683CB87D4735.png" width="501" height="442" title="Val04_6-1707974897371.png" alt="Val04_6-1707974897371.png"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Graph of CPU&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428410i694DEE3C71FADA3F.png?width=530&amp;amp;height=468&amp;amp;name=428410i694DEE3C71FADA3F.png" width="530" height="468" title="Val04_7-1707974897373.png" alt="Val04_7-1707974897373.png"&gt;&lt;/p&gt; 
&lt;p&gt;From kali, we will go to the netbot folder directory and edit the netbot_config.py file to set the target IP address and port 8080.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Edit nebot_config.py File&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428412i3D11FBBBFC6EB5B7.png?width=541&amp;amp;height=100&amp;amp;name=428412i3D11FBBBFC6EB5B7.png" width="541" height="100" title="Val04_8-1707974897374.png" alt="Val04_8-1707974897374.png"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;br&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428415i3B8AB0F7C10728EA.png?width=707&amp;amp;height=373&amp;amp;name=428415i3B8AB0F7C10728EA.png" width="707" height="373" title="Val04_9-1707974897380.png" alt="Val04_9-1707974897380.png"&gt;&lt;/p&gt; 
&lt;p&gt;In this stage, we will start up the NetBot server which is the netbot_server.py python script as it will be where the botnets will connect to. We will be able to view how many bots are connected in the server.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;netbot Server&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428414i7DF036F2F1B301DA.png?width=506&amp;amp;height=157&amp;amp;name=428414i7DF036F2F1B301DA.png" width="506" height="157" title="Val04_10-1707974897381.png" alt="Val04_10-1707974897381.png"&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;a&gt;&lt;/a&gt;&lt;strong&gt;1&lt;sup&gt;st&lt;/sup&gt; bot (Ubuntu)&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The first bot is using Ubuntu. We will go to the netbot folder directory and edit the file netbot_client.py. For this file, we will set the host IP address which is the server and leave the port as default. This will allow the bot to be connected to the server.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Edit netbot_config.py Command&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428413i9EF8F325F1F5D4A8.png?width=499&amp;amp;height=101&amp;amp;name=428413i9EF8F325F1F5D4A8.png" width="499" height="101" title="Val04_11-1707974897382.png" alt="Val04_11-1707974897382.png"&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Edit Host IP Address&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428418iB4F90B4FD72D87C5.png?width=626&amp;amp;height=309&amp;amp;name=428418iB4F90B4FD72D87C5.png" width="626" height="309" title="Val04_12-1707974897386.png" alt="Val04_12-1707974897386.png"&gt;&lt;/p&gt; 
&lt;p&gt;Once the python script has been edited, we will run the netbot_client.py python script. In Figure 3.4, we can see that currently the server sends a “HALT” response. This response means that the attack is stopped, will not send the attack to the target machine.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Response from NetBot Server&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428417iE8086BFC4B186597.png?width=563&amp;amp;height=114&amp;amp;name=428417iE8086BFC4B186597.png" width="563" height="114" title="Val04_13-1707974897387.png" alt="Val04_13-1707974897387.png"&gt;&lt;/p&gt; 
&lt;p&gt;At the server side, we are able to see that the IP address and port number of the bot that is connected to the server.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;First Bot Connected to Server&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428416i47A3057B3382634F.png?width=571&amp;amp;height=146&amp;amp;name=428416i47A3057B3382634F.png" width="571" height="146" title="Val04_14-1707974897388.png" alt="Val04_14-1707974897388.png"&gt;&lt;/p&gt; 
&lt;p&gt;From here, we will be able start the DDoS attack. To start the attack, we will edit netbot_config.py python script and change the ATTACK_CODE to “LAUNCH”. This will start the DDoS HTTP flood attack to the server of the target.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Change ATTACK_CODE to “LAUNCH”&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428421iBB2C78327AAAFDFE.png?width=722&amp;amp;height=380&amp;amp;name=428421iBB2C78327AAAFDFE.png" width="722" height="380" title="Val04_15-1707974897393.png" alt="Val04_15-1707974897393.png"&gt;&lt;/p&gt; 
&lt;p&gt;In the Ubuntu bot, we can see that the attack has started after the change of the ATTACK_CODE which the bot is now sending HTTP request to the targeted server.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Response Changed to “LAUNCH”&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428420i044A150CF15D86D6.png?width=666&amp;amp;height=328&amp;amp;name=428420i044A150CF15D86D6.png" width="666" height="328" title="Val04_16-1707974897395.png" alt="Val04_16-1707974897395.png"&gt;&lt;/p&gt; 
&lt;p&gt;Looking at the response time of the server, we can see that the response time increased after the attack started. Before the attack, the average response time was about 0.34 seconds, but currently the response time has increased to about 0.64 seconds.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Current Response Time After Start of Attack&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428419i3F47335A769EBFB9.png?width=446&amp;amp;height=213&amp;amp;name=428419i3F47335A769EBFB9.png" width="446" height="213" title="Val04_17-1707974897396.png" alt="Val04_17-1707974897396.png"&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;a&gt;&lt;/a&gt;&lt;strong&gt;2&lt;sup&gt;nd&lt;/sup&gt; bot (CentOS 7)&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The second bot is using CentOS 7. The steps are similar to the Ubuntu bot by editing the netbot_client.py python script, setting the host IP address.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Edit netbot_client.py Command&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428424i50B5473643844F80.png?width=725&amp;amp;height=122&amp;amp;name=428424i50B5473643844F80.png" width="725" height="122" title="Val04_18-1707974897398.png" alt="Val04_18-1707974897398.png"&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Edit Host IP Address&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428422iE1B6BAEA14328D5A.png?width=770&amp;amp;height=383&amp;amp;name=428422iE1B6BAEA14328D5A.png" width="770" height="383" title="Val04_19-1707974897400.png" alt="Val04_19-1707974897400.png"&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;After editing the python script, will run it and from here, we can see that the server immediately sends the response to “LAUNCH” the attack since the first bot is already sending request packets to the target server.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Response from NetBot Server&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428423i460B52B7A5818FC3.png?width=739&amp;amp;height=159&amp;amp;name=428423i460B52B7A5818FC3.png" width="739" height="159" title="Val04_20-1707974897401.png" alt="Val04_20-1707974897401.png"&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;From the server, the second bot has already been added into the list in the server with its IP address and port number.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Second Bot Connected to Server&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428427i52AD8337CDDBDC38.png?width=636&amp;amp;height=218&amp;amp;name=428427i52AD8337CDDBDC38.png" width="636" height="218" title="Val04_21-1707974897403.png" alt="Val04_21-1707974897403.png"&gt;&lt;/p&gt; 
&lt;p&gt;With two bots attacking, the response time of the server increased again. where with first bot sending request packets, its respond time is 0.64 seconds and adding the second bot increased to about 1.10 seconds.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Increased Response Time with Two Bots&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428426i6E86595BFED91B90.png?width=492&amp;amp;height=332&amp;amp;name=428426i6E86595BFED91B90.png" width="492" height="332" title="Val04_22-1707974897404.png" alt="Val04_22-1707974897404.png"&gt;&lt;/p&gt; 
&lt;p&gt;In the target machine, with the DDoS attack still running, we can see that the CPU increased all the way to 100%, where the server is running on the command prompt is at 88.5%. This affects the performance of the applications and servers running in the machine, might cause lag and overheating to it.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;CPU Running at Full Capacity&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428425i1D44E94DC8BA53E6.png?width=551&amp;amp;height=488&amp;amp;name=428425i1D44E94DC8BA53E6.png" width="551" height="488" title="Val04_23-1707974897406.png" alt="Val04_23-1707974897406.png"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Graph of CPU at 100%&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428429i2530B4C00E8EABA3.png?width=566&amp;amp;height=492&amp;amp;name=428429i2530B4C00E8EABA3.png" width="566" height="492" title="Val04_24-1707974897407.png" alt="Val04_24-1707974897407.png"&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;Analysis&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;In the network traffic that has been captured, it shows the IP addresses that are connected to the HTTP website by sending GET requests packets to the HTTP website.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Network Traffic (Send Request Packets)&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428428i761822459C66E4A7.png?width=1174&amp;amp;height=135&amp;amp;name=428428i761822459C66E4A7.png" width="1174" height="135" title="Val04_25-1707974897409.png" alt="Val04_25-1707974897409.png"&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;In one of the packets, it shows that the request was sent to the host with the IP address 192.168.1.45 to the server at port 8080. Once the request is sent, the server sends back a response which will allow the IP address 192.168.1.0 to have access to the HTTP website.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Network Traffic Information&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428430iE62DAED1C04DB526.png?width=756&amp;amp;height=308&amp;amp;name=428430iE62DAED1C04DB526.png" width="756" height="308" title="Val04_26-1707974897413.png" alt="Val04_26-1707974897413.png"&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;The next set of network traffic shows that the two bots are connected to the server through the destination port 5555.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Network Traffic (Bots Connected)&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428432iAFC7E0E19B46EE50.png?width=779&amp;amp;height=111&amp;amp;name=428432iAFC7E0E19B46EE50.png" width="779" height="111" title="Val04_27-1707974897414.png" alt="Val04_27-1707974897414.png"&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;In the packets, we can see that a command was sent to both bots, to do a HTTP flood on the target server IP address 192.168.1.45 at port 8080. The “HALT” command shows that the attack is paused, and the “LAUNCH” command shows that the attack will start immediately to flood the server. From the second bot, the “LAUNCH” command was sent immediately as it was connected to server after the attack has started.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Network Traffic Information (Bot 1)&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428431i58D0F68F65447B50.png?width=866&amp;amp;height=301&amp;amp;name=428431i58D0F68F65447B50.png" width="866" height="301" title="Val04_28-1707974897416.png" alt="Val04_28-1707974897416.png"&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Network Traffic Information (Bot 2)&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428433i4EEF7786057F79C7.png?width=868&amp;amp;height=306&amp;amp;name=428433i4EEF7786057F79C7.png" width="868" height="306" title="Val04_29-1707974897418.png" alt="Val04_29-1707974897418.png"&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;Rule Creation&lt;a&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;For the detection of the DDoS attack that was done, we will create an ESA rule that detects through the destination port, for the HTTP requests that was sent to the server. As there is a possibility that the DDoS traffic are encrypted, we will make use of the web server to detect on the number of HTTP request packets was sent within 1 minute and try track down the number of source IP addresses are sending these requests.&lt;/p&gt; 
&lt;p&gt;A post on Cloudflare's blog reports that over 60% of the attacks are under 500 Mbps, and almost 30% of the attacks are between 500 Mbps and 10 Gbps. The largest attack they have seen recently was about 550 Gbps. Source:&amp;nbsp;&lt;a href="https://blog.cloudflare.com/ddos-attacks-have-evolved-and-so-should-your-ddos-protection/"&gt;https://blog.cloudflare.com/ddos-attacks-have-evolved-and-so-should-your-ddos-protection/&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;Take note that for a DDOS, the typical requests will be coming in at more than 1M requests per second, so in this case it is advisable to input in 60M requests (60000000) in the field&amp;nbsp;"Occurs".&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;It is helpful to include the list of webservers IP address if known.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Also, the rule would need to be written to group by destination IP.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;ESA Rule – DDoS Attack Detected&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/429632iDFE695788853CB4C.png?width=591&amp;amp;height=297&amp;amp;name=429632iDFE695788853CB4C.png" width="591" height="297" title="Lawrence_2-1714962084553.png" alt="Lawrence_2-1714962084553.png"&gt;&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/429631iFC4286727697F172.png?width=595&amp;amp;height=294&amp;amp;name=429631iFC4286727697F172.png" width="595" height="294" title="Lawrence_1-1714962066078.png" alt="Lawrence_1-1714962066078.png"&gt;&lt;/p&gt; 
&lt;div&gt;
  &amp;nbsp; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50269063&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmydev.netwitness.com%2Fnetwitness-security-llc-blog%2Fddosusingbotnetusecase&amp;amp;bu=https%253A%252F%252Fmydev.netwitness.com%252Fnetwitness-security-llc-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 07 May 2024 04:00:00 GMT</pubDate>
      <guid>https://mydev.netwitness.com/netwitness-security-llc-blog/ddosusingbotnetusecase</guid>
      <dc:date>2024-05-07T04:00:00Z</dc:date>
      <dc:creator>Admin</dc:creator>
    </item>
    <item>
      <title>HYDRA Brute Force</title>
      <link>https://mydev.netwitness.com/netwitness-security-llc-blog/hydrabruteforce</link>
      <description>&lt;h2&gt;INTRODUCTION&lt;/h2&gt; 
&lt;p&gt;Hydra stands as a formidable tool in the arsenal of cybersecurity professionals and hackers alike, renowned for its prowess in brute-force attacks. Leveraging its versatile capabilities, Hydra can systematically probe login interfaces of various protocols and services, relentlessly attempting to crack passwords through exhaustive trial and error. Its adaptability extends across a wide spectrum, encompassing HTTP, HTTPS, FTP, SSH, Telnet, SMTP, and numerous other authentication mechanisms, making it a versatile option for penetrating diverse systems and applications.&lt;/p&gt;</description>
      <content:encoded>&lt;h2&gt;INTRODUCTION&lt;/h2&gt; 
&lt;p&gt;Hydra stands as a formidable tool in the arsenal of cybersecurity professionals and hackers alike, renowned for its prowess in brute-force attacks. Leveraging its versatile capabilities, Hydra can systematically probe login interfaces of various protocols and services, relentlessly attempting to crack passwords through exhaustive trial and error. Its adaptability extends across a wide spectrum, encompassing HTTP, HTTPS, FTP, SSH, Telnet, SMTP, and numerous other authentication mechanisms, making it a versatile option for penetrating diverse systems and applications.&lt;/p&gt; 
&lt;p&gt;Hydra traces its origins back to the early days of cybersecurity exploration and penetration testing, emerging as a vital tool in the arsenal of ethical hackers and security professionals. Developed by van Hauser, also known as Thorsten Schroeder, in the late 1990s, Hydra was conceived as an open-source project aimed at providing a robust and flexible solution for conducting brute-force attacks against various authentication systems. Originally designed to support a limited set of protocols, Hydra's capabilities rapidly expanded over the years, thanks to the contributions of an active community of developers and security enthusiasts. Its evolution mirrored the escalating sophistication of cybersecurity threats and the growing need for comprehensive testing tools to assess the resilience of digital defenses.&lt;/p&gt; 
&lt;p&gt;Today, Hydra stands as a testament to the collaborative spirit of the cybersecurity community, embodying years of refinement and innovation in the pursuit of enhancing digital security practices and fortifying systems against malicious intrusions.&lt;/p&gt; 
&lt;p&gt;This blog will also Cover AS-REP roasting where epitomizes a sophisticated attack vector within the realm of Active Directory environments, leveraging weaknesses in Kerberos authentication. This technique targets accounts configured with "Do not require Kerberos pre-authentication" enabled, allowing adversaries to request AS-REP (Authentication Service Response) tickets without presenting any valid credentials.&lt;/p&gt; 
&lt;p&gt;By exploiting this vulnerability, attackers can capture encrypted AS-REP tickets for targeted user accounts. When armed with a password list, attackers can then systematically decrypt these tickets offline, leveraging the captured hashes and the passwords contained within the list to compromise user accounts.&lt;/p&gt; 
&lt;p&gt;This method poses a significant threat, particularly in environments where weak or easily guessable passwords are prevalent. As organizations increasingly rely on Active Directory for authentication and access control, understanding and mitigating AS-REP Roasting attacks with password lists is paramount to maintaining robust cybersecurity defenses.&lt;/p&gt; 
&lt;h2&gt;Brute Force&lt;/h2&gt; 
&lt;p&gt;Brute forcing credentials represents a persistent and often effective method employed by attackers to gain unauthorized access to systems, accounts, or sensitive information. This technique involves systematically trying an exhaustive number of possible combinations of usernames and passwords until the correct credentials are discovered.&lt;/p&gt; 
&lt;p&gt;By leveraging automated tools like Hydra or specialized scripts, attackers can rapidly cycle through vast sets of potential passwords, exploiting weaknesses in authentication systems. Brute forcing is particularly potent against weak or commonly used passwords, highlighting the critical importance of robust password policies, multi-factor authentication, and other security measures to mitigate the risk of unauthorized access. Despite its simplicity, brute forcing remains a prevalent threat in the cybersecurity landscape, underscoring the ongoing need for vigilance and proactive defenses to safeguard against credential-based attacks.&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428441i0176ED2255BF9023.png?width=653&amp;amp;height=240&amp;amp;name=428441i0176ED2255BF9023.png" width="653" height="240" title="TeckSeng_0-1707981564448.png" alt="TeckSeng_0-1707981564448.png"&gt;&lt;/p&gt; 
&lt;p&gt;Brute Force Attack&lt;/p&gt; 
&lt;h2&gt;HYDRA Attack&lt;/h2&gt; 
&lt;p&gt;A scan on the network will be to look for any ports or protocols that can be exploited and brute forced to gain initial access into the system.&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428442i1EF0C7D8E5F9CE8A.png?width=731&amp;amp;height=95&amp;amp;name=428442i1EF0C7D8E5F9CE8A.png" width="731" height="95" title="TeckSeng_1-1707981564450.png" alt="TeckSeng_1-1707981564450.png"&gt;&lt;/p&gt; 
&lt;p&gt;NMAP Scan&lt;/p&gt; 
&lt;p&gt;In this case, we see that port 22 (SSH) is open. This is good news for attackers as this means that remote access to the device is enabled if the right credentials are entered.&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428443i65227DAC6F2F8663.png?width=415&amp;amp;height=384&amp;amp;name=428443i65227DAC6F2F8663.png" width="415" height="384" title="TeckSeng_2-1707981564452.png" alt="TeckSeng_2-1707981564452.png"&gt;&lt;/p&gt; 
&lt;p&gt;Scan Result&lt;/p&gt; 
&lt;p&gt;The command entered below is to direct hydra to use a username list to run it against a password list (obtained from Rock You in Kali) and match each user to a password to find valid credentials which we can use to log in. In this case, hydra has discovered that we have a hit in one of the username and password list by the name of jack.&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428446i72935799235130FE.png?width=855&amp;amp;height=186&amp;amp;name=428446i72935799235130FE.png" width="855" height="186" title="TeckSeng_3-1707981564457.png" alt="TeckSeng_3-1707981564457.png"&gt;&lt;/p&gt; 
&lt;p&gt;HYDRA brute-forcing&lt;/p&gt; 
&lt;p&gt;Command Entered:&lt;/p&gt; 
&lt;table&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="601"&gt; &lt;p&gt;hydra -L username_list.txt -P password_list.txt ssh://192.168.1.11&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428445iC1C80E3BA2D508CF.png?width=440&amp;amp;height=154&amp;amp;name=428445iC1C80E3BA2D508CF.png" width="440" height="154" title="TeckSeng_4-1707981564459.png" alt="TeckSeng_4-1707981564459.png"&gt;&lt;/p&gt; 
&lt;p&gt;SSH into Compromised Account&lt;/p&gt; 
&lt;p&gt;We can see that we managed to gain Initial Access into the devices via the stolen credentials.&lt;/p&gt; 
&lt;h2&gt;AS-REP Attack&lt;/h2&gt; 
&lt;p&gt;An AS-REP attack with authentication to the Key Distribution Center (KDC) exploits vulnerabilities in the Kerberos authentication protocol used in Active Directory environments. Typically, when a user attempts to authenticate to a service, the client sends a request to the KDC for a Ticket Granting Ticket (TGT).&lt;/p&gt; 
&lt;p&gt;The KDC responds by encrypting a TGT using the user's password hash. However, certain accounts may be configured with the "Do not require Kerberos preauthentication" attribute enabled, meaning the KDC doesn't require the client to prove knowledge of the password before issuing the TGT.&lt;/p&gt; 
&lt;p&gt;In an AS-REP attack, an attacker can send a forged authentication request to the KDC for a TGT without providing valid credentials. The KDC, unaware of the absence of preauthentication, responds by encrypting a TGT using the user's password hash.&lt;/p&gt; 
&lt;p&gt;The attacker can then capture this encrypted TGT and attempt to crack it offline to retrieve the user's plaintext password, potentially gaining unauthorized access to the user's account. This attack underscores the importance of securing accounts and properly configuring authentication mechanisms within Active Directory environments to mitigate such vulnerabilities.&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hubfs/Imported_Blog_Media/428444i7C62BD7FE9ADDAF9.png" title="TeckSeng_5-1707981564460.png" alt="TeckSeng_5-1707981564460.png"&gt;&lt;/p&gt; 
&lt;p&gt;KDC Key Exchange&lt;/p&gt; 
&lt;p&gt;We will be using Impacket to carry out this attack. In an Impacket GETnpusers attack, adversaries exploit vulnerabilities in the way Active Directory handles certain types of Kerberos tickets. Specifically, this attack targets the Kerberos AS-REQ (Authentication Service Request) message sent by clients to the Key Distribution Center (KDC) to request service tickets.&lt;/p&gt; 
&lt;p&gt;By sending a forged AS-REQ message with specific flags, attackers can trick the KDC into providing a special type of ticket, known as a TGT (Ticket Granting Ticket), without presenting valid credentials. This TGT can then be used to request service tickets for any user in the domain, even without knowing their passwords. Impacket's GETnpusers tool automates this process, allowing attackers to quickly harvest TGTs and enumerate users within the domain.&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428449i901E966A05E78829.png?width=838&amp;amp;height=440&amp;amp;name=428449i901E966A05E78829.png" width="838" height="440" title="TeckSeng_6-1707981564475.png" alt="TeckSeng_6-1707981564475.png"&gt;&lt;/p&gt; 
&lt;p&gt;AS-REP Attack&lt;/p&gt; 
&lt;h2&gt;Analysis (Brute Force)&lt;/h2&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428447i40911749FBD42709.png?width=918&amp;amp;height=323&amp;amp;name=428447i40911749FBD42709.png" width="918" height="323" title="TeckSeng_7-1707981564480.png" alt="TeckSeng_7-1707981564480.png"&gt;&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;Brute Force SSH logs captured on NetWitness system.&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428448i773DBC7E174FA46D.png?width=963&amp;amp;height=413&amp;amp;name=428448i773DBC7E174FA46D.png" width="963" height="413" title="TeckSeng_8-1707981564487.png" alt="TeckSeng_8-1707981564487.png"&gt;&lt;/p&gt; 
&lt;p&gt;Brute Force SSH logs captured on NetWitness system.&lt;/p&gt; 
&lt;p&gt;From the 2 images above, we are able to see that there are a lot of SSH connection coming through in the form of “sshd.exe -y” and “sshd.exe -r”. The sshd.exe -y option is used to generate host keys for the OpenSSH server on Windows. When you run sshd.exe -y, it will create host key files if they don't already exist. The &lt;strong&gt;-R&lt;/strong&gt; option is used with the &lt;strong&gt;sshd&lt;/strong&gt; (OpenSSH server) to specify remote port forwarding.&lt;/p&gt; 
&lt;p&gt;Remote port forwarding allows a connection from the server to a remote client, creating a tunnel for the specified ports. In normal traffic, one or two ssh connections are normal, but, as we can see from the logs, there are hundreds of SSH connections coming in in a span of seconds.&lt;/p&gt; 
&lt;h2&gt;Analysis (AS-REP)&lt;/h2&gt; 
&lt;p&gt;In an AS-REP attack scenario with a username list, adversaries exploit vulnerabilities in Active Directory authentication to compromise user accounts. Armed with a list of usernames harvested through reconnaissance or other means, attackers systematically submit requests for AS-REP tickets for each user in the list. These tickets contain encrypted hashes of the user's password. Subsequently, attackers can offline decrypt these tickets using specialized tools and techniques, potentially uncovering weak or easily guessable passwords associated with the targeted user accounts.&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428452i7815A80233DC0B6B.png?width=905&amp;amp;height=373&amp;amp;name=428452i7815A80233DC0B6B.png" width="905" height="373" title="TeckSeng_9-1707981564493.png" alt="TeckSeng_9-1707981564493.png"&gt;&lt;/p&gt; 
&lt;p&gt;AS-REP Roasting Enumeration&lt;/p&gt; 
&lt;p&gt;When a valid username is found to be part of the domain, the server will reply the client, which in this case is the attacker, with a AS-REP reply. This reply is then intercepted, and the hash of the user can be cracked offline giving the attacker an entry into the network.&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428451iC342DE9CD878B345.png?width=926&amp;amp;height=81&amp;amp;name=428451iC342DE9CD878B345.png" width="926" height="81" title="TeckSeng_10-1707981564495.png" alt="TeckSeng_10-1707981564495.png"&gt;&lt;/p&gt; 
&lt;p&gt;Successful AS-REP from server&lt;/p&gt; 
&lt;h2&gt;Possible Rules to Detect for SSH Brute Force&lt;/h2&gt; 
&lt;p&gt;The rule created is to detect for SSH brute Force. Specific Meta keys are picked out to detect for anomalies within the network for a possible brute force attack on.&lt;/p&gt; 
&lt;h3&gt;&lt;a&gt;&lt;/a&gt;ESA Rule&lt;/h3&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428459i5E402127CB3E6DCD.png?width=643&amp;amp;height=315&amp;amp;name=428459i5E402127CB3E6DCD.png" width="643" height="315" title="TeckSeng_19-1707981780126.png" alt="TeckSeng_19-1707981780126.png"&gt;&lt;/p&gt; 
&lt;h3&gt;&lt;a&gt;&lt;/a&gt;Rule Syntax&lt;/h3&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428460i898BA0EC4E3C3AC9.png?width=698&amp;amp;height=286&amp;amp;name=428460i898BA0EC4E3C3AC9.png" width="698" height="286" title="TeckSeng_20-1707981780131.png" alt="TeckSeng_20-1707981780131.png"&gt;&lt;/p&gt; 
&lt;p&gt;Threshold set&lt;/p&gt; 
&lt;table&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="601"&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; @Name('Module_77b66f53_5fdc_4c8e_a05f_c926e780c3c4_Alert')&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; @Description('')&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; @RSAAlert(oneInSeconds=0)&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SELECT * FROM Event(&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /* Statement: SSH Brute Force */&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (isOneOfIgnoreCase(filename_src,{ 'sshd.exe' }) AND isOneOfIgnoreCase(directory_dst,{ 'C:\\Windows\\System32:\\OpenSSH\\' }) AND isOneOfIgnoreCase(param_src,{ 'sshd.exe \"-R\"' }) AND isOneOfIgnoreCase(param_dst,{ 'sshd.exe \"-y\"' }))&lt;/p&gt; &lt;p&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;)&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h3&gt;&amp;nbsp;&lt;/h3&gt; 
&lt;h3&gt;&lt;a&gt;&lt;/a&gt;Rule Test&lt;/h3&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428461iC524E32F4099068B.png?width=757&amp;amp;height=380&amp;amp;name=428461iC524E32F4099068B.png" width="757" height="380" title="TeckSeng_21-1707981780137.png" alt="TeckSeng_21-1707981780137.png"&gt;&lt;/p&gt; 
&lt;p&gt;Possible Rules to Detect for AS-REP Roasting&lt;/p&gt; 
&lt;p&gt;The meta keys chosen for this rule is specifically to pick up on behaviour associated with AS_REP Roasting with enumeration within the network.&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428464iA7D3D781C2952F08.png?width=669&amp;amp;height=326&amp;amp;name=428464iA7D3D781C2952F08.png" width="669" height="326" title="TeckSeng_22-1707981780139.png" alt="TeckSeng_22-1707981780139.png"&gt;&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428462i895EB50B8371F498.png?width=630&amp;amp;height=310&amp;amp;name=428462i895EB50B8371F498.png" width="630" height="310" title="TeckSeng_23-1707981780140.png" alt="TeckSeng_23-1707981780140.png"&gt;&lt;/p&gt; 
&lt;h3&gt;&lt;a&gt;&lt;/a&gt;Rule syntax&lt;/h3&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428463i8385951562BADBD1.png?width=533&amp;amp;height=245&amp;amp;name=428463i8385951562BADBD1.png" width="533" height="245" title="TeckSeng_24-1707981780143.png" alt="TeckSeng_24-1707981780143.png"&gt;&lt;/p&gt; 
&lt;h3&gt;&lt;a&gt;&lt;/a&gt;Rule Test&lt;/h3&gt; 
&lt;p&gt;&amp;nbsp;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/428465iCF28DC5C8020E723.png?width=662&amp;amp;height=219&amp;amp;name=428465iCF28DC5C8020E723.png" width="662" height="219" title="TeckSeng_25-1707981780146.png" alt="TeckSeng_25-1707981780146.png"&gt;&lt;/p&gt; 
&lt;table&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="601"&gt; &lt;p&gt;&amp;nbsp; &amp;nbsp;module Module_65b620a6e4b0c8e3c269fd3e;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; @Name('Module_65b620a6e4b0c8e3c269fd3e_Alert')&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; @Description('')&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; @RSAAlert(oneInSeconds=0)&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SELECT * FROM Event(&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /* Statement: Suspected Domain Brute Force */&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (isOneOfIgnoreCase(action,{ 'kerberos as request' }) AND error.toLowerCase() IN ( 'kdc err c principal unknown' ) AND ( 'kerberos as reply' != ALL( action ) ) AND ad_username_dst.toLowerCase() IN ( 'krbtgt' ) AND tcp_dstport IN ( 88 ))&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OR&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /* Statement: Successful Login */&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (( 'kerberos as reply' = ANY( action ) ) AND ( 'kerberos as reply' = ANY( action ) ))&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ).win:time(1 Minutes)&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MATCH_RECOGNIZE (&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PARTITION BY ip_src&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MEASURES E1 as e1_data , E2 as e2_data&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PATTERN (E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1 E2* E1+ E2)&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DEFINE&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E1 as (isOneOfIgnoreCase(E1.action,{ 'kerberos as request' }) AND E1.error.toLowerCase() IN ( 'kdc err c principal unknown' ) AND ( 'kerberos as reply' != ALL( E1.action ) ) AND E1.ad_username_dst.toLowerCase() IN ( 'krbtgt' ) AND E1.tcp_dstport IN ( 88 )),&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E2 as (( 'kerberos as reply' = ANY( E2.action ) ) AND ( 'kerberos as reply' = ANY( E2.action ) ))&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; );&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50269063&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmydev.netwitness.com%2Fnetwitness-security-llc-blog%2Fhydrabruteforce&amp;amp;bu=https%253A%252F%252Fmydev.netwitness.com%252Fnetwitness-security-llc-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 07 May 2024 04:00:00 GMT</pubDate>
      <guid>https://mydev.netwitness.com/netwitness-security-llc-blog/hydrabruteforce</guid>
      <dc:date>2024-05-07T04:00:00Z</dc:date>
      <dc:creator>Admin</dc:creator>
    </item>
    <item>
      <title>A Closer Look at Advanced EPL (ESA) Through a Rule and its Components</title>
      <link>https://mydev.netwitness.com/netwitness-security-llc-blog/acloserlookatadvancedepl-esa-througharuleanditscomponents</link>
      <description>&lt;p&gt;It is no secret that getting your head around the capabilities or syntax of Esper EPL can be difficult and that finding examples which fit your needs can be just as hard. Even then, you may still be left with more questions than answers. In this blog, we take a look at a rule from an educational perspective. With the information provided, you should be able to massage the rule into a variety of use cases or apply the concepts to brand new requirements.&amp;nbsp;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It is no secret that getting your head around the capabilities or syntax of Esper EPL can be difficult and that finding examples which fit your needs can be just as hard. Even then, you may still be left with more questions than answers. In this blog, we take a look at a rule from an educational perspective. With the information provided, you should be able to massage the rule into a variety of use cases or apply the concepts to brand new requirements.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;A quick note about documentation: Google queries have often led me to old versions of the Esper documentation so double check the URL when you're following links. Here's a link to the latest documentation and I'd particularly suggest reading section 2. &lt;a href="https://esper.espertech.com/release-8.9.0/reference-esper/html_single/"&gt;https://esper.espertech.com/release-8.9.0/reference-esper/html_single/&lt;/a&gt;&lt;/p&gt; 
&lt;h2&gt;Context&lt;/h2&gt; 
&lt;p&gt;Alerts based on the rate of traffic matching an arbitrary query can be useful for SOC monitoring suspicious activity or engineering teams ensuring proper data flow. This rule is meant to act similar to Health &amp;amp; Wellness alarms to avoid repetitive alerting:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;A threshold condition (total event count) is met within a time period&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;The condition is sustained for a number of time periods&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;An alert fires and &lt;u&gt;will not fire again&lt;/u&gt; until the condition resolves (count falls below the threshold)&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Follow-up actions from this alert should include a manual query to better assess the situation causing the rule to fire. Alternatively, integration with SOAR could trigger queries or reports to obtain the relevant information.&lt;/p&gt; 
&lt;h2&gt;Memory Management&lt;/h2&gt; 
&lt;p&gt;This rule was specifically designed without the use of sliding or batch time windows due to their high memory overhead which traditionally require time windows to be short and without a large number of events. Given that only a count is being kept here, it should be suitable for high rates and long periods with little performance impact. However, as always, the rule should be deployed as a trial rule and monitored closely after the initial deployment.&lt;/p&gt; 
&lt;p&gt;At the time of this writing, I've observed that there are only specific situations where the Java engine is able to collect statistics from the rule.&amp;nbsp; This might make more sense as you read further but imagine the following events in the window, where S is stat collection start, E is end, and F T T T is the search pattern. &lt;/p&gt; 
&lt;pre&gt;            * * * *                 * * * * &lt;br&gt;F F F T F T F T T T T T F T T F T T F T T T T T T F F&lt;br&gt;                  S     E                 S       E&lt;/pre&gt; 
&lt;p&gt;I've talked to the engineering team about this and it appears to be a limitation of objects exposed from the Esper engine to the NetWitness integration while the search pattern is incomplete. Regardless, during the periods where statistics are available, I've found this rule is only using 25-100KB of memory and very little CPU, even when matching over 1,000,000 events per hour.&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;Future Enhancements&lt;/h2&gt; 
&lt;p&gt;Future enhancements could include modifying the rule to alert when a rate is sustained below a threshold (easy), dynamically calculating the threshold based on standard deviation (complicated), or considering the pass/fail criteria based on followed-by or otherwise complex conditions.&amp;nbsp; The rule could also be simplified by alerting on a total count within a time period or set of periods and then using &lt;code&gt;@RSAAlert&lt;/code&gt; to suppress alerts for an acceptable period of time. Otherwise, for the purpose of alerting on a sustained rate above a threshold, the sample rule provided here is easily customizable to fit other use cases by modifying the event filter criteria.&lt;/p&gt; 
&lt;h2&gt;Example&lt;/h2&gt; 
&lt;p&gt;Consider an example where the rule is looking for time periods containing more than 700 events matching the selection criteria and sustained for two periods. Also requiring the two periods to be preceded by a period that failed to meet the threshold prevents the alert from firing again until the situation causing the elevated rate has ended.&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hubfs/Imported_Blog_Media/429049i172B32321B5F21F4.png" title="example_chart.png" alt="example_chart.png"&gt;&lt;/p&gt; 
&lt;p&gt;The below example is looking for three 60-minute periods containing at least 500,000 events. The event criteria is inbound DNS with the &lt;code&gt;error = "no name"&lt;/code&gt; meta. The &lt;code&gt;error&lt;/code&gt; meta key is a multivalued meta key and, as such, will need to be defined in the correlation service. Don’t forget to sync the keys when this value is updated in the service config.&amp;nbsp;&lt;a href="https://community.netwitness.com/s/article/UpdateYourESARulesfortheRequiredMulti-ValueandSingle-ValueMetaKeys"&gt;https://community.netwitness.com/s/article/UpdateYourESARulesfortheRequiredMulti-ValueandSingle-ValueMetaKeys&lt;/a&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Including &lt;code&gt;direction IS NOT NULL&lt;/code&gt; may or may not be required. In the past, it was advised to ensure that at least one condition in a statement would match to avoid EPL errors. I will update the blog if I get clarification on this point.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hubfs/Imported_Blog_Media/429050iE19679A532308AEA.png" title="correlation server settings.png" alt="correlation server settings.png"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hubfs/Imported_Blog_Media/429051i27925B160F5EF5E4.png" title="meta key sync.png" alt="meta key sync.png"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;WARNING: &lt;/strong&gt;If you are deploying multiple versions of this rule, the named window, context, variable, and schema names must be unique because these are global structures shared by the ESA deployment. In a text editor, you can find/replace "Rule#" to avoid issues.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;The comments in the rule below explain each component used, or should at least give you enough information to find the relevant sections in the Esper EPL documentation.&amp;nbsp;&lt;/p&gt; 
&lt;pre&gt;&lt;code&gt;//If you are deploying multiple versions of this rule, the following must be unique because these are globally shared by the ESA deployment. Update all occurrences in the rule by replacing "rule#" with a unique rule number: //  window names //  context names //  variable names //  schema names //Modify the variables, the FROM clause in the statement with the event filter criteria, and the pattern match occurrences (numbers in {#} next to E1/E2). //This alert will NOT populate the Respond alert with actual session data. It will simply notify you that your criteria has been met which should then be followed up with a manual query. //If the rule is deployed when the matching traffic rate is already above the threshold, the rule will not begin tracking until the rate drops below the threshold again. //The time period must contain at least this many sessions in order to insert a "True" value into the history window. CREATE VARIABLE integer var_session_threshold_rule1 = 500000; //The length of time that must pass before the final comparison of the total number of sessions in the window against the threshold. CREATE VARIABLE integer var_window_minutes_rule1 = 60; //100 should be large enough to handle most use cases. This window's main purpose is to hold True/False values for the match_recognize statement. //It is intentionally not part of the context because we need to track results spanning multiple context instances. //@RSAPersist will keep the contents of the window stored on the ESA appliance at /var/netwitness/correlation-server/esa-windows/. When the service restarts, the window contents will be restored from the file. //When the stored events are written back into the window (oldest to newest), this will trigger the SELECT statement and may fire alerts. The @RSAAlert suppression would likely mean only one alert would fire. //It is not necessary to use @RSAPersist but it can be helpful for debugging through service restarts. @RSAPersist CREATE WINDOW thresholdHistoryWindow_rule1.win:length(100) (bool_exceeded bool, window_ending string, matched_count long); //Contexts are a way to segment event streams. In this case, we start a context as soon as the rule deploys, terminate it after the defined number of minutes, and start a new one after the defined number of minutes. CREATE CONTEXT contextTimePeriod_rule1 INITIATED @now AND PATTERN [every timer:at(*/var_window_minutes_rule1, *, *, *, *)] TERMINATED after var_window_minutes_rule1 minutes; //By including an operator (&amp;gt;=) in the SELECT clause, the result of the statement becomes a boolean value which is then inserted into the history window. //"Event(...)" means that only sessions matching the criteria in parentheses will be counted. //Esper EPL maintains a count of matching events via count(). It will not retain the events (thus reducing memory requirements) unless a batch or sliding window are created. //OUTPUT LAST WHEN TERMINATED prevents the SELECT clause result from being inserted until the context terminates. //Newlines/indentation are not necessary but help make the rule easier to read. Note that the statement begins at CONTEXT and ends with the semicolon after TERMINATED. CONTEXT contextTimePeriod_rule1 INSERT INTO thresholdHistoryWindow_rule1 SELECT count(*) &amp;gt;= var_session_threshold_rule1 as bool_exceeded, current_timestamp().toDate().toString() as window_ending, count(*) as matched_count FROM Event(direction IS NOT NULL AND isOneOfIgnoreCase(error,{ 'no name' }) AND direction.toLowerCase() IN ( 'inbound' ) AND service IN ( 53 )) OUTPUT LAST WHEN TERMINATED; //oneInSeconds=600 prevents alert spam in case the rule behaves unintentionally. //match_recognize is used to ensure that the pattern is matched explicitly in the order described without any intermediate events being considered for the match. //Modify the numbers in curly braces {#} in the pattern to set how many occurrences of each event are needed for the alert to fire. @RSAAlert(oneInSeconds=600) SELECT * FROM thresholdHistoryWindow_rule1 MATCH_RECOGNIZE( MEASURES E1 as e1_data, E2 as e2_data PATTERN ( E1{1} E2{3}) DEFINE E1 as (E1.bool_exceeded = false), E2 as (E2.bool_exceeded = true) );&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;Note: If you plan to use this rule in the online EPL tryout tool,&amp;nbsp;&lt;a href="https://esper-epl-tryout.appspot.com/epltryout/mainform.html"&gt;EsperTech Esper EPL Online&lt;/a&gt;, you will need to use &lt;code&gt;direction IN ( 'inbound' )&lt;/code&gt;because the toLowerCase() function is custom (but built into the ESA deployment). The @RSAAlert annotation should be removed as well. Sample input for the tryout tool is attached but is not maintained to exactly match the rule above so you may need to adjust it.&lt;/p&gt; 
&lt;p&gt;Also, you should understand how the @RSAPersist annotation behaves, especially if you use it in other ESA rules.&amp;nbsp;&lt;a href="https://community.netwitness.com/s/article/ESAAnnotations"&gt;ESA Annotations.&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;After deploying rules with named windows, you can use the Named Windows tool under the ESA Rules tab of the UI to view the window contents. In this screenshot, I have a field called "windowEnding" but later changed the script above to "window_ending" for consistency.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hubfs/Imported_Blog_Media/429054iF3D365BB8CCDB4BB.png" title="esa data window.png" alt="esa data window.png"&gt;&lt;/p&gt; 
&lt;h2&gt;Summary&lt;/h2&gt; 
&lt;p&gt;Hopefully you learned something from this dissection of an ESA rule and can see how its concepts could be applied to other use cases. I thought it was important to share not only what works, but why certain methods were chosen and which methods didn't work. The use of contexts here instead of sliding or batch windows, as well as the match_recognize syntax, should provide a good deal of flexibility. If you implement a version of this rule, please share your use case and experience!&amp;nbsp;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50269063&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmydev.netwitness.com%2Fnetwitness-security-llc-blog%2Facloserlookatadvancedepl-esa-througharuleanditscomponents&amp;amp;bu=https%253A%252F%252Fmydev.netwitness.com%252Fnetwitness-security-llc-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Wed, 13 Mar 2024 04:00:00 GMT</pubDate>
      <guid>https://mydev.netwitness.com/netwitness-security-llc-blog/acloserlookatadvancedepl-esa-througharuleanditscomponents</guid>
      <dc:date>2024-03-13T04:00:00Z</dc:date>
      <dc:creator>DanielSpier</dc:creator>
    </item>
    <item>
      <title>FirstWatch Threat Spotlight – Remcos RAT</title>
      <link>https://mydev.netwitness.com/netwitness-security-llc-blog/702009</link>
      <description>&lt;p&gt;&lt;strong&gt;Summary:&lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Summary:&lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Remcos&lt;/strong&gt; is a closed-source tool that is marketed as a remote control and surveillance software by a Germany-based firm called &lt;strong&gt;Breaking Security&lt;/strong&gt;. Remcos has been observed being used in malware campaigns with a wide array of functionalities.&lt;br&gt;&lt;br&gt;&lt;/p&gt; 
&lt;p&gt;On the Breaking Security website, &lt;strong&gt;Remcos or Remote Control and Surveillance tool&lt;/strong&gt;, is marketed as a professional and &lt;strong&gt;legitimate tool&lt;/strong&gt; for remotely managing Windows systems but it is now widely used in multiple malicious campaigns by threat actors. Remcos RAT is a sophisticated remote access Trojan (RAT) that can be used to fully control and monitor any Windows computer from XP and onwards. On this webpage, it provides two versions: professional edition (with all features included) and free edition (with restricted features).&lt;br&gt;&lt;br&gt;&lt;/p&gt; 
&lt;p&gt;Remcos RAT is recognized as a malware family because it has been &lt;strong&gt;abused by hackers&lt;/strong&gt; to secretly control victims’ devices since its first version was published on July 21, 2016.&lt;br&gt;&lt;br&gt;&lt;/p&gt; 
&lt;p&gt;Remcos RAT is designed to be stealthy and evasive, making it difficult for antivirus software and other security measures to detect and remove it. It is typically delivered through social engineering techniques, such as phishing emails or malicious downloads.&lt;br&gt;&lt;br&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Features / Capabilities:&lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Once installed on a victim's system, Remcos RAT provides the attacker with a wide range of capabilities, including:&lt;br&gt;&lt;br&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;System:&lt;/strong&gt; Screen Capture, &lt;strong&gt;File Manager&lt;/strong&gt;, File Search, Process Manager, etc.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Surveillance:&lt;/strong&gt; Webcam, Microphone, &lt;strong&gt;Keylogger&lt;/strong&gt;, &lt;strong&gt;Screenlogger&lt;/strong&gt;, etc.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Network:&lt;/strong&gt; Proxy, Downloader, Open Webpage, etc.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Others:&lt;/strong&gt; Dll Loader, Logins Cleaner, Audio Player, etc.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Heartbeat packet: &lt;/strong&gt;Provides an inter-nodal communication packet.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Unauthorized Access:&lt;/strong&gt; Attackers can gain complete control of the victim's computer remotely, allowing them to access files, folders, and applications as if they were physically present at the machine.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Ransomware Deployment:&lt;/strong&gt; In some cases, attackers may use Remcos RAT to deliver and install ransomware on the victim's system, encrypting their files and demanding a ransom for decryption.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Banking Fraud:&lt;/strong&gt; Remcos RAT can be used to perform fraudulent transactions by gaining access to the victim's online banking accounts.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Network Scanning:&lt;/strong&gt; Remcos RAT can scan the local network to identify other vulnerable devices.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;DDoS Attacks:&lt;/strong&gt; Some versions of Remcos RAT have been known to include DDoS capabilities, allowing attackers to use the compromised machines as part of a botnet to launch distributed denial-of-service attacks.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Spreading Malware:&lt;/strong&gt; Attackers can use Remcos RAT as a gateway to drop additional malware onto the victim's system, infecting it with more harmful software.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Privilege Escalation:&lt;/strong&gt; Remcos RAT may be used to escalate privileges on the compromised system, enabling the attacker to gain administrator or root access for more control over the device.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Keylogging:&lt;/strong&gt; Remcos RAT can capture all keystrokes made by the victim, including login credentials, credit card numbers, and other sensitive information. This enables attackers to steal valuable data.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;File Management:&lt;/strong&gt; Attackers can access, download, and upload files on the compromised system, potentially stealing sensitive data or dropping additional malware.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Surveillance:&lt;/strong&gt; Remcos RAT can remotely enable the victim's webcam and microphone, allowing attackers to spy on the victim's activities and conversations.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Screen Capture:&lt;/strong&gt; Attackers can take screenshots of the victim's desktop, providing them with visual information about the victim's activities and potentially sensitive data.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Please refer to below images for more &lt;strong&gt;features/capabilities of Remcos RAT&lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/425918i8C6B3A0871B23FAC.png?width=671&amp;amp;height=327&amp;amp;name=425918i8C6B3A0871B23FAC.png" width="671" height="327" title="manojpilli_0-1692704990519.png" alt="manojpilli_0-1692704990519.png"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Figure 1: Surveillance capabilities of Remcos RAT.&lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/425919i2CD62439A4570A35.png?width=671&amp;amp;height=327&amp;amp;name=425919i2CD62439A4570A35.png" width="671" height="327" title="manojpilli_1-1692705134198.png" alt="manojpilli_1-1692705134198.png"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Figure 2: System capabilities of Remcos RAT.&lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Detection:&lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;There are many articles on the internet covering how Remcos RAT can be delivered. Here in this article, I will be covering what happens when Remcos RAT is being run on the victim host and the ways attackers can use this RAT to get the system information, along with NetWitness detections covering several of it's typical activities.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Activities done by Remcos RAT during initial execution on the victim device:&lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Geo-location:&lt;/strong&gt; Remcos RAT will try to get the victim machine geo location to register with attackers by sending a get request to geoplugin.net for location check by the infected Windows host. &lt;br&gt;&lt;br&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;img src="https://static.hsstatic.net/BlogImporterAssetsUI/ex/missing-image.png" width="653" height="128" title="manojpilli_0-1692705441197.jpeg" alt="manojpilli_0-1692705441197.jpeg"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Figure: Geo-location capabilities of Remcos RAT&lt;br&gt;&lt;/strong&gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NetWitness can detect this activity with the rule &lt;strong&gt;"Host traffic to external IP checker”.&lt;/strong&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Persistence:&lt;/strong&gt; The malware adds a Startup registry key at “HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce” for it to become persistent when the device affected has been restarted. This path can be changed during the agent build process.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NetWitness can detect this activity with &lt;strong&gt;"Remcos RAT Persistence registry entry"&lt;/strong&gt;.&amp;nbsp;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;During the installation of this software a specific registry key is set in place related to the licensing of this software. The rule &lt;strong&gt;"Remcos rat creates run key"&lt;/strong&gt; detects agent/client install at the compromised host. With custom monitoring of these registry entries, we can get to know if the host is compromised with remcos or not as shown in the below image.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/425922iF68B605727A7DDF9.png?width=652&amp;amp;height=303&amp;amp;name=425922iF68B605727A7DDF9.png" width="652" height="303" title="manojpilli_1-1692705441220.png" alt="manojpilli_1-1692705441220.png"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; Figure 3: Remcos RAT registry entry along with Netwitness detection.&lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Detecting sensitive information that, it could steal from a victim's machine.&lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;DxDiag:&lt;/strong&gt; DirectX Diagnostic Tool (DxDiag) is a diagnostics tool used to test DirectX functionality and troubleshoot video- or sound-related hardware problems. DirectX Diagnostic can save text files with the scan results which contains current DirectX version, the computer's hostname, the operating system's version, information on the system BIOS, and other data. AS it is legitimate tool to use on windows machine, Remcos RAT exploits Dxdiag to obtains the above-mentioned information.&amp;nbsp; &lt;br&gt;&lt;br&gt;&lt;img src="https://static.hsstatic.net/BlogImporterAssetsUI/ex/missing-image.png" width="654" height="359" title="manojpilli_0-1692804315741.jpeg" alt="manojpilli_0-1692804315741.jpeg"&gt; &lt;p&gt;&lt;strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Figure 4: Detection of the activity "Enumeration of System Information using Dxdiag"&lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Keylogging:&lt;/strong&gt; This Remcos RAT has another feature for keylogging and grabbing the clipboard data that will be placed in the%appdata%\remcos folder named as logs.dat file. It also serves as a debug log for Remcos RAT for actions like clearing browser history and so on. Below is the snippet of logs.dat while testing this feature. [References [3]]&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;img src="https://mydev.netwitness.com/hubfs/Imported_Blog_Media/425924iDA558E53B7148E94.png" title="manojpilli_3-1692705763139.png" alt="manojpilli_3-1692705763139.png"&gt;&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Figure 5: Remcos RAT keylogging capabilities&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; With the rule “&lt;strong&gt;Remcos RAT keylog File Creation&lt;/strong&gt;” Netwitness can detect this activity.&lt;br&gt;&lt;br&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Audio Recording:&lt;/strong&gt; Remcos RAT can record the victim’s audio input from an input device ( microphone). This behavior was seen in multiple Remcos RAT malware samples where it put the audio recording in the appdata\audio folder as part of data collection. This recording can be sent to its C2 server as part of its exfiltration to the compromised machine. Creation of wav files in this folder path is not a usual place for the user to save an audio format file.&lt;br&gt;&lt;br&gt;The rule &lt;strong&gt;“Suspicious audio file creation in temporary folders&lt;/strong&gt;” can detect a suspicious creation of .wav file in appdata folder.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Screenshots:&lt;/strong&gt; The attacker can capture a screenshot of the compromised machine and place it in the appdata folder, where it will be sent to its C2 server. This TTP is really a good indicator to check that process because it is in suspicious folder path and image files are not commonly created by a user in this folder path.&lt;br&gt;&lt;br&gt;The rule &lt;strong&gt;“Suspicious image file creation in temp folders” &lt;/strong&gt;can detect a suspicious creation of .wav file in appdata folder.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;UAC Bypass:&lt;/strong&gt; This RAT can Bypass UAC by &lt;strong&gt;modifying the&lt;/strong&gt; "&lt;strong&gt;EnableLua" registry value to disable UAC&lt;/strong&gt; on the compromised machine.&lt;br&gt;&lt;br&gt;The rule &lt;strong&gt;“Silently accepting end user license”&lt;/strong&gt; detects any application accepting end user license agreement on a Windows host.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;strong&gt;Remcos C2 Console usage Detection:&lt;br&gt;&lt;br&gt; &lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;DNS Query:&lt;/strong&gt; A specific DNS query was also detected during the installation process, specifically directed towards &lt;strong&gt;p4-preview.runhosting.com&lt;/strong&gt;. Some other products from the same vendor have also been observed in this domain as well.&amp;nbsp;&lt;br&gt;&lt;br&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://static.hsstatic.net/BlogImporterAssetsUI/ex/missing-image.png" width="656" height="357" title="manojpilli_0-1692706256723.jpeg" alt="manojpilli_0-1692706256723.jpeg"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Figure 6&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://static.hsstatic.net/BlogImporterAssetsUI/ex/missing-image.png" width="656" height="354" title="manojpilli_1-1692706256730.jpeg" alt="manojpilli_1-1692706256730.jpeg"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Figure 7&lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;NetWitness Detections&lt;/strong&gt;&lt;br&gt;&lt;br&gt;&lt;/p&gt; 
&lt;p&gt;After analyzing samples from various sources and referring to research articles, following are existing NetWitness Detections that aid in identifying not just Remcos RAT’s malicious activity, but other adversaries as well that might be part of similar techniques.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Application Rules (Endpoint):&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "Disables UAC"&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "Potential Windows User Account Control Bypass"&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "Creates Run Key"&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "Windows Executable Runs Command Shell" &lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "Lists Directory Structure of a Path"&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "Disables UAC Remote Restrictions" &lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "unsigned writes executable to appdatalocal directory"&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "Host Traffic to External IP Checker"&lt;/p&gt; 
&lt;p&gt;In addition to the existing content, we have also created new rules as mentioned above to better detect host and network activity related to Remcos RAT. All of the following are currently available from NetWitness Live. After deploying/importing these rules on to NetWitness stack, these can be seen under I&lt;strong&gt;nvestigate -&amp;gt; Navigate&lt;/strong&gt; upon detecting any Remcos RAT related activity on the customer environment.&lt;/p&gt; 
&lt;p&gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "enumeration_of_sys_info_using_dxdiag"&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (App Rule - Endpoint)&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "remcos_rat_c2_console_usage_detected"&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (App Rule - Packet)&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "remcos_rat_creates_run_key"&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (App Rule - Endpoint)&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "remcos_rat_keylog_file_creation"&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (App Rule - Endpoint)&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "remcos_rat_persistence_registry_entry"&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (App Rule - Endpoint)&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "suspicious_audio_file_creation_in_temp_folders"&amp;nbsp;&amp;nbsp; (App Rule - Endpoint)&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; boc = "suspicious_image_file_creation_in_temp_folders"&amp;nbsp; (App Rule - Endpoint)&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [Community] Remcos RAT YARA Rules&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;MITRE ATT&amp;amp;CK Information:&lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;table width="954"&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="170"&gt; &lt;p&gt;&lt;strong&gt;Tactic&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;&lt;strong&gt;T. ID&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;&lt;strong&gt;Technique Name&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;&lt;strong&gt;Activity&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="170"&gt; &lt;p&gt;&lt;strong&gt;Persistance&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1547.001&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos can add itself to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for persistence.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="2" width="170"&gt; &lt;p&gt;&lt;strong&gt;Execution&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1059.003&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Command and Scripting Interpreter: Windows Command Shell&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos can launch a remote command line to execute commands on the victim’s machine.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1059.006&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Command and Scripting Interpreter: Python&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos uses Python scripts.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="4" width="170"&gt; &lt;p&gt;&lt;strong&gt;Defence Evasion&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1112&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Modify Registry&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos has full control of the Registry, including the ability to modify it.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1027&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Obfuscated Files or Information&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos uses RC4 and base64 to obfuscate data, including Registry entries and file paths.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1548.002&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Abuse Elevation Control Mechanism: Bypass User Account Control&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos has a command for UAC bypassing.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1055&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Process Injection&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos has a command to hide itself through injecting into another process.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="2" width="170"&gt; &lt;p&gt;&lt;strong&gt;Discovery&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1083&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;File and Directory Discovery&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos can search for files on the infected machine.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1497.001&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Virtualization/Sandbox Evasion: System Checks&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos searches for Sandboxie and VMware on the system.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="5" width="170"&gt; &lt;p&gt;&lt;strong&gt;Collection&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1123&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Audio Capture&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos can capture data from the system’s microphone.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1115&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Clipboard Data&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos steals and modifies data from the clipboard.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1056.001&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Input Capture: Keylogging&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos has a command for keylogging.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1113&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Screen Capture&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos takes automated screenshots of the infected machine.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1125&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Video Capture&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos can access a system’s webcam and take pictures.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="2" width="170"&gt; &lt;p&gt;&lt;strong&gt;Command and Control&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1090&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Proxy&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos uses the infected hosts as SOCKS5 proxies to allow for tunneling and proxying.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="85"&gt; &lt;p&gt;T1105&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="236"&gt; &lt;p&gt;Ingress Tool Transfer&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="463"&gt; &lt;p&gt;Remcos can upload and download files to and from the victim’s machine.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;&lt;br&gt;&lt;br&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Conclusion: &lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Remcos or Remote Control and Surveillance, marketed as a legitimate software by Germany-based Breaking Security for remotely managing Windows systems is now widely used in multiple malicious campaigns by threat actors. Remcos RAT is a sophisticated remote access Trojan (RAT) that can be used to fully control and monitor any Windows computer from XP and onwards.&lt;br&gt;&lt;br&gt;&lt;/p&gt; 
&lt;p&gt;Currently many threat actors are utilizing social engineering techniques to deliver this payload. It is our responsibility to prevent and detect the activities done by threat actors using Remcos RAT.&lt;br&gt;&lt;br&gt;&lt;/p&gt; 
&lt;p&gt;In this blog, we examined Remcos RAT and how it can be used by threat actors to gain access to victim’s host. Next, we covered its features and capabilities in detail through activities done during installation and operation, and NetWitness detections for them as well as C2 console usage detection. Finally, we listed Mitre attack framework TTP's for Remcos RAT.&lt;br&gt;&lt;br&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;References: &lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;[1] &lt;a title="Remcos, Software S0332 | MITRE ATT&amp;amp;CK" href="https://attack.mitre.org/software/S0332/"&gt;Remcos, Software S0332 | MITRE ATT&amp;amp;CK&lt;/a&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;[2] &lt;a href="https://www.fortinet.com/blog/threat-research/latest-remcos-rat-phishing"&gt;The Latest Remcos RAT Driven By Phishing Campaign | FortiGuard Labs&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;[3] &lt;a href="https://www.splunk.com/en_us/blog/security/splunk-fin7-tool-detections-remcos.html"&gt;Detecting Remcos Tool Used by FIN7 with Splunk | Splunk&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;[4] &lt;a href="https://research.splunk.com/stories/remcos/"&gt;Remcos - Splunk Security Content&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;[5] &lt;a title="Remcos | Remote Control &amp;amp; Surveillance Software" href="https://breakingsecurity.net/remcos/"&gt;Remcos | Remote Control &amp;amp; Surveillance Software&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;[6] &lt;a href="https://tria.ge"&gt;Triage&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;[7] &lt;a href="https://any.run/malware-trends/remcos"&gt;Remcos Malware Analysis, Overview by ANY.RUN&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50269063&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmydev.netwitness.com%2Fnetwitness-security-llc-blog%2F702009&amp;amp;bu=https%253A%252F%252Fmydev.netwitness.com%252Fnetwitness-security-llc-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 22 Aug 2023 04:00:00 GMT</pubDate>
      <guid>https://mydev.netwitness.com/netwitness-security-llc-blog/702009</guid>
      <dc:date>2023-08-22T04:00:00Z</dc:date>
      <dc:creator>manojpilli</dc:creator>
    </item>
    <item>
      <title>Content Hygiene – Application Rule Alert Mapping Updates</title>
      <link>https://mydev.netwitness.com/netwitness-security-llc-blog/700525</link>
      <description>&lt;p&gt;To help facilitate future content improvements such as new bundles and feeds, we have adjusted the alert meta mappings for several Application Rules. &amp;nbsp;By more strictly adhering to the original intention for the alert detection categories, NetWitness users will gain more meaningful and accurate insights into activity within their environments. Rules were re-aligned with the Hunting Compromise and Analysis Keys:&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;To help facilitate future content improvements such as new bundles and feeds, we have adjusted the alert meta mappings for several Application Rules. &amp;nbsp;By more strictly adhering to the original intention for the alert detection categories, NetWitness users will gain more meaningful and accurate insights into activity within their environments. Rules were re-aligned with the Hunting Compromise and Analysis Keys:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;u&gt;Behavior of Compromise (&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;)&lt;/u&gt;: Designated for suspect or nefarious behavior outside the standard signature-based detection&lt;/li&gt; 
 &lt;li&gt;&lt;u&gt;Service Analysis (&lt;strong&gt;&lt;em&gt;analysis.service&lt;/em&gt;&lt;/strong&gt;)&lt;/u&gt;: Core application protocols identification and inspection&lt;/li&gt; 
 &lt;li&gt;&lt;u&gt;Session Analysis (&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;)&lt;/u&gt;: Client-server communication deviations&lt;/li&gt; 
 &lt;li&gt;&lt;u&gt;File Analysis (&lt;strong&gt;&lt;em&gt;analysis.file&lt;/em&gt;&lt;/strong&gt;)&lt;/u&gt;: A large inspection library that highlights file characteristics and anomalies&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h4&gt;&lt;strong&gt;&lt;u&gt;Updated Application Rules&lt;/u&gt;&lt;/strong&gt;:&lt;/h4&gt; 
&lt;table&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1"&gt; &lt;p&gt;&lt;strong&gt;Name&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt; &lt;p&gt;&lt;strong&gt;Previous Key&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;New Key&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;exe filetype but not exe extension&lt;strong&gt;*&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.file&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Small Executable&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.file&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Small Executable Extension Mismatch&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.file&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Small Executable No Directory&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.file&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Small Executable No Host&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.file&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Small Executable Root Directory&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.file&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;DoH Usage&lt;strong&gt;*&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.service&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;IRC File Transfer&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.service&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Passwords Over FTP&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.service&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Passwords Over HTTP&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.service&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Passwords Over Other Protocols&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.service&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Passwords Over Pop3&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.service&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Passwords Over SMTP&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.service&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Passwords Over Telnet&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.service&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Possible SMB Scanning Detected&lt;strong&gt;*&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.service&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;BYOD Mobile Web Agent Detected&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Possible Port Scanning Detected&lt;strong&gt;*&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;suspicious long filename get request&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;suspicious PHP url-encoded put&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Unknown Service Over DNS Port&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Unknown Service Over FTP Port&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Unknown Service Over HTTP Port&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Unknown Service Over IRC Port&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Unknown Service Over NNTP Port&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Unknown Service Over POP3 Port&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Unknown Service Over SMB Port&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Unknown Service Over SMTP Port&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Unknown Service Over SSL Port&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Unknown Service Over Telnet Port&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;analysis.session&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Archive From IP Address&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Attachment Overload&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;File Transport Over Unknown Protocol&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - DHCP&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - DNS&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - FTP&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - H323&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - HTTP&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - IRC&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - NetBios&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - NNTP&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - POP3&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - RDP&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - RIP&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - RPC&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - RTP&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - SIP&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - SMB&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - SMTP&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - SNMP&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - SSH&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - SSL&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - TDS&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - Telnet&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - TFTP&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1" width="250"&gt; &lt;p&gt;Non-Standard Port Use - TNS&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="100"&gt; &lt;p&gt;&lt;em&gt;alert.id&lt;/em&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1" width="206"&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;boc&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;&lt;strong&gt;*&lt;/strong&gt; - Users subscribed to these alerts will have rules automatically updated&lt;/p&gt; 
&lt;p&gt;&lt;u&gt;Note&lt;/u&gt; - Application Rules formerly keyed to ‘alert.id’ will need to be added from NetWitness Live.&lt;/p&gt; 
&lt;h4&gt;&lt;strong&gt;&lt;u&gt;Removed Content&lt;/u&gt;&lt;/strong&gt;&lt;/h4&gt; 
&lt;p&gt;As an additional content hygiene measure, the following outdated/discontinued content has been removed from NetWitness Live:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;u&gt;Advanced Analytics (Warehouse) / Data Science Model&lt;/u&gt; 
  &lt;ul&gt; 
   &lt;li&gt;&lt;em&gt;ETL for Mapr&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;ETL&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;ETL for Pivotal&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Host Profile for Mapr&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Host Profile for Pivotal&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Suspicious DNS Activity for Mapr&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Suspicious DNS Activity for Pivotal&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Suspicious Domains for Mapr&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Suspicious Domains for Pivotal&lt;/em&gt;&lt;/li&gt; 
  &lt;/ul&gt; &lt;/li&gt; 
 &lt;li&gt;&lt;u&gt;Application Rules&lt;/u&gt; 
  &lt;ul&gt; 
   &lt;li&gt;&lt;em&gt;HttpBrowser Malware&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;NTP DDoS Attack 234-byte Request: Packets&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;NTP DDoS Attack 50-byte Request: Packets&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;NTP DDoS Attack 60-byte Request: Packets&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;NTP DDoS Attack 234-byte Request: Netflow&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;NTP DDoS Attack 50-byte Request: Netflow&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;NTP DDoS Attack 60-byte Request: Netflow&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Large Outbound Encrypted session&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Large Outbound Session&lt;/em&gt;&lt;/li&gt; 
  &lt;/ul&gt; &lt;/li&gt; 
 &lt;li&gt;&lt;u&gt;Event Stream Analysis&lt;/u&gt; 
  &lt;ul&gt; 
   &lt;li&gt;&lt;em&gt;Cerber Ransomware&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Inbound Packet Followed by Recipient Outbound Encrypted Connection&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Internal Data Posting to 3rd party sites&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Malware Dropper&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Web DoS Alert&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;BYOD Mobile Web Agent Detected&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Detection of Encrypted Traffic to Countries&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Multiple SYN packets from Same Source&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Potential HTTP Slow Post DoS&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Detect Port Knocking Packet&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Punycode Phishing Attempt&lt;/em&gt;&lt;/li&gt; 
  &lt;/ul&gt; &lt;/li&gt; 
 &lt;li&gt;&lt;u&gt;Investigation Column Group&lt;/u&gt; 
  &lt;ul&gt; 
   &lt;li&gt;&lt;em&gt;Email Analysis Column Group&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Endpoint Analysis Column Group&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Web Analysis Group Column&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Malware Analysis Column Group&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Threat Analysis Column Group&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;User and Entity Behaviour Analysis Column Group&lt;/em&gt;&lt;/li&gt; 
  &lt;/ul&gt; &lt;/li&gt; 
 &lt;li&gt;&lt;u&gt;Lua Parsers&lt;/u&gt; 
  &lt;ul&gt; 
   &lt;li&gt;&lt;em&gt;Poison_Ivy&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;plugx&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;rekaf&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;struts_exploit&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;pvid&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;MSU_rat&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;CustomTCP&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;supercmd&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;china_chopper&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;apt_artifacts&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;cerber&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;duqu_lua&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;electricfish&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Evilgrab&lt;/em&gt;&lt;/li&gt; 
  &lt;/ul&gt; &lt;/li&gt; 
 &lt;li&gt;&lt;u&gt;NetWitness Reports&lt;/u&gt; 
  &lt;ul&gt; 
   &lt;li&gt;&lt;em&gt;Malware Activity Report&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Large Outbound Connections to 3rd Party Sites Sessions&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Large Outbound Encrypted Sessions&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Large Outbound Sessions&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Hunting Summary&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Hunting Detail&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Encrypted Traffic&lt;/em&gt;&lt;/li&gt; 
  &lt;/ul&gt; &lt;/li&gt; 
 &lt;li&gt;&lt;u&gt;NetWitness Rules&lt;/u&gt; 
  &lt;ul&gt; 
   &lt;li&gt;&lt;em&gt;Large Outbound Encrypted Sessions&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Large Outbound Sessions&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Malware Activity DNS&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Malware Activity Unidentified&lt;/em&gt;&lt;/li&gt; 
   &lt;li&gt;&lt;em&gt;Malware Activity Web&lt;/em&gt;&lt;/li&gt; 
  &lt;/ul&gt; &lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50269063&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmydev.netwitness.com%2Fnetwitness-security-llc-blog%2F700525&amp;amp;bu=https%253A%252F%252Fmydev.netwitness.com%252Fnetwitness-security-llc-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 11 Jul 2023 04:00:00 GMT</pubDate>
      <guid>https://mydev.netwitness.com/netwitness-security-llc-blog/700525</guid>
      <dc:date>2023-07-11T04:00:00Z</dc:date>
      <dc:creator>DarrenMccutchen</dc:creator>
    </item>
    <item>
      <title>Microsoft Azure Log Analytics workspace integration with Netwitness</title>
      <link>https://mydev.netwitness.com/netwitness-security-llc-blog/microsoftazureloganalyticsworkspaceintegrationwithnetwitness</link>
      <description>&lt;p&gt;&lt;strong&gt;Azure Log Analytics workspace&lt;/strong&gt; is a unique environment for log data from Azure Monitor and other Azure services, such as Microsoft Sentinel, Microsoft Defender and Azure Kubernetes for Cloud. Each workspace has its own data repository and configuration but might combine data from multiple Azure services. Log Analytics can be used to edit and run log queries with the data in Azure monitor logs. With Azure Log Analytics you can easily sort, filter, and provide analysis to a simple query returning a set of records.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Azure Log Analytics workspace&lt;/strong&gt; is a unique environment for log data from Azure Monitor and other Azure services, such as Microsoft Sentinel, Microsoft Defender and Azure Kubernetes for Cloud. Each workspace has its own data repository and configuration but might combine data from multiple Azure services. Log Analytics can be used to edit and run log queries with the data in Azure monitor logs. With Azure Log Analytics you can easily sort, filter, and provide analysis to a simple query returning a set of records.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;NetWitness Platform XDR&lt;/strong&gt;&amp;nbsp;enables log collection from Azure Log Analytics workspace through the log analytics API. The plugin module which is used to call the API, generates a query to fetch a specific type of log from a specific table. Log analytics workspace can contain logs from different sources and each source might have a different table name. For example, to collect Azure Kubernetes logs, customers should first forward&amp;nbsp;Azure Kubernetes Service (AKS) logs to the Log Analytics workspace (follow the detailed instructions in the plugin documentation below). In NetWitness Platform XDR, the customer should enter the table name as “&lt;i&gt;AzureDiagnostics&lt;/i&gt;” and the log types from the list,&amp;nbsp;&lt;i&gt;"kube-apiserver", "kube-audit","kube-audit-admin","kube-scheduler","guard"&lt;/i&gt;. Make sure that you enter the logs types separated by a comma without any space, example:&amp;nbsp;&lt;i&gt;kube-apiserver&lt;/i&gt;,&lt;i&gt;kube-audit&lt;/i&gt;. To know more information about Azure Log Analytics workspace integration, please refer to the documentation references provided at the end of this blog.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Integration model:&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://mydev.netwitness.com/hs-fs/hubfs/Imported_Blog_Media/424990i9C607203910F7E04.png?width=810&amp;amp;height=255&amp;amp;name=424990i9C607203910F7E04.png" width="810" height="255" title="AditGhildiyal8_0-1684298101310.png" alt="AditGhildiyal8_0-1684298101310.png"&gt;&lt;/p&gt; 
&lt;p&gt;Events are collected in JSON format. Customers should enable &lt;strong&gt;azure parser&lt;/strong&gt; in NetWitness log decoder to parse the collected events.&lt;/p&gt; 
&lt;p&gt;Documentation:&lt;/p&gt; 
&lt;p&gt;1.&amp;nbsp;&lt;strong&gt;&lt;a href="https://community.netwitness.com/s/article/MicrosoftAzureLogAnalyticsWokspaceEventSourceLogConfigurationGuide"&gt;Log Analytics Plugin Documentation&lt;/a&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;2.&amp;nbsp;&lt;strong&gt;&lt;a href="https://learn.microsoft.com/en-us/azure/azure-monitor/logs/log-analytics-workspace-overview"&gt;About Log Analytics workspace&lt;/a&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Log Collector Package on Netwitness Live: "Log Collector configuration content for event source MS Azure Loganalytics"&lt;/p&gt; 
&lt;p&gt;Log Parser on Netwitness Live: azure&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50269063&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmydev.netwitness.com%2Fnetwitness-security-llc-blog%2Fmicrosoftazureloganalyticsworkspaceintegrationwithnetwitness&amp;amp;bu=https%253A%252F%252Fmydev.netwitness.com%252Fnetwitness-security-llc-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Thu, 25 May 2023 04:00:00 GMT</pubDate>
      <guid>https://mydev.netwitness.com/netwitness-security-llc-blog/microsoftazureloganalyticsworkspaceintegrationwithnetwitness</guid>
      <dc:date>2023-05-25T04:00:00Z</dc:date>
      <dc:creator>Admin</dc:creator>
    </item>
    <item>
      <title>File Activity Alert Optimization in Multi-EPS Deployment</title>
      <link>https://mydev.netwitness.com/netwitness-security-llc-blog/fileactivityalertoptimizationinmulti-epsdeployment</link>
      <description>&lt;p&gt;In 12.1 and older versions, if a file present on a host such as Host 1 was found malicious or suspicious after performing a YARA scan or an OPSWAT scan, an alert was triggered with &lt;strong&gt;YARA alert match&lt;/strong&gt; or &lt;strong&gt;OPSWAT alert match&lt;/strong&gt; respectively only in that particular host. If the same file is present on multiple hosts such as Host 2, Host 3, and Host 4, the &lt;strong&gt;YARA alert match&lt;/strong&gt; or &lt;strong&gt;OPSWAT alert match&lt;/strong&gt; notifications were not triggered in these hosts.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In 12.1 and older versions, if a file present on a host such as Host 1 was found malicious or suspicious after performing a YARA scan or an OPSWAT scan, an alert was triggered with &lt;strong&gt;YARA alert match&lt;/strong&gt; or &lt;strong&gt;OPSWAT alert match&lt;/strong&gt; respectively only in that particular host. If the same file is present on multiple hosts such as Host 2, Host 3, and Host 4, the &lt;strong&gt;YARA alert match&lt;/strong&gt; or &lt;strong&gt;OPSWAT alert match&lt;/strong&gt; notifications were not triggered in these hosts.&lt;/p&gt; 
&lt;p&gt;Instead, the notifications &lt;strong&gt;Process with matched YARA rule &lt;/strong&gt;or&lt;strong&gt; Process with OPSWAT reported suspicious/malicious&lt;/strong&gt; were triggered respectively on multiple hosts every time when the YARA or OPSWAT matched file activities were detected on any Hosts such as Host1, Host2, Host 3, and Host 4. As a result, it was difficult for analysts working on multiple hosts to triage other important alerts as the notifications &lt;strong&gt;Process with matched YARA rule &lt;/strong&gt;or&lt;strong&gt; Process with OPSWAT reported suspicious/malicious&lt;/strong&gt; were frequently triggered and displayed in the UI whenever some YARA or OPSWAT matched file activities were detected on any Hosts such as Host1, Host2, Host 3, and Host 4.&lt;/p&gt; 
&lt;p&gt;The notifications &lt;strong&gt;Process with matched YARA rule &lt;/strong&gt;or&lt;strong&gt; Process with OPSWAT reported suspicious/malicious &lt;/strong&gt;were triggered even on the new Hosts such as Host 5 or Host 6 whenever some YARA or OPSWAT matched file activities were detected on any Hosts such as Host1, Host2, Host 3, and Host 4.&lt;/p&gt; 
&lt;p&gt;From 12.2 or later versions, the notifications across multiple hosts are optimized. The alert &lt;strong&gt;YARA alert match&lt;/strong&gt; or &lt;strong&gt;OPSWAT alert match&lt;/strong&gt; is triggered across multiple hosts such as Host 1, Host 2, Host 3, and Host 4 as soon as the file present on any host such as Host 1 is found to be malicious or suspicious after performing a YARA scan or an OPSWAT scan. Later, even if the YARA or OPSWAT matched file activities are detected on any host such as Host 1, the notifications &lt;strong&gt;Process with matched YARA rule &lt;/strong&gt;or&lt;strong&gt; Process with OPSWAT reported suspicious/malicious &lt;/strong&gt;are not triggered in any of the hosts. With this enhancement, the analysts can now triage the alerts appropriately with just one notification of &lt;strong&gt;YARA alert match&lt;/strong&gt; or &lt;strong&gt;OPSWAT alert match&lt;/strong&gt;. &amp;nbsp;&lt;/p&gt; 
&lt;p&gt;If the malicious file is present in the new host such as Host 5, the alert &lt;strong&gt;YARA alert match&lt;/strong&gt; or &lt;strong&gt;OPSWAT alert match&lt;/strong&gt; is triggered even in the new host as soon as the Endpoint server detects the malicious file in the new host.&lt;/p&gt; 
&lt;p&gt;To avoid triggering &lt;strong&gt;Process with OPSWAT reported suspicious/malicious &lt;/strong&gt;notifications in the multiple hosts whenever some OPSWAT matched file activities were detected on a particular host, the following Endpoint App rules are deleted.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;process with opswat reported infected&lt;/strong&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;process with opswat reported suspicious&lt;/strong&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;To avoid triggering &lt;strong&gt;Process with matched YARA rule &lt;/strong&gt;notifications in the multiple hosts whenever some YARA matched file activities were detected on a particular host, the following Endpoint App rule is deleted.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;process with matched yara rule&lt;/strong&gt;&lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50269063&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmydev.netwitness.com%2Fnetwitness-security-llc-blog%2Ffileactivityalertoptimizationinmulti-epsdeployment&amp;amp;bu=https%253A%252F%252Fmydev.netwitness.com%252Fnetwitness-security-llc-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Thu, 16 Mar 2023 04:00:00 GMT</pubDate>
      <guid>https://mydev.netwitness.com/netwitness-security-llc-blog/fileactivityalertoptimizationinmulti-epsdeployment</guid>
      <dc:date>2023-03-16T04:00:00Z</dc:date>
      <dc:creator>Admin</dc:creator>
    </item>
    <item>
      <title>Threat Profile Series: An Introduction to Royal Ransomware</title>
      <link>https://mydev.netwitness.com/netwitness-security-llc-blog/threatprofileseries-anintroductiontoroyalransomware</link>
      <description>&lt;p&gt;Towards the end of 2022, &lt;a href="https://socradar.io/dark-web-profile-royal-ransomware/"&gt;researchers at SOCRadar&lt;/a&gt; recognized a relatively new cyber gang, Royal, as the most active ransomware threat. Attacks linked to Royal Ransomware have impacted a diverse pool of victims across many geographical regions and multiple industrial sectors, including healthcare and public healthcare , education, communications, and manufacturing, among others. Recently, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) released their &lt;a href="https://www.cisa.gov/sites/default/files/2023-03/aa23-061a-stopransomware-royal-ransomware.pdf"&gt;second joint advisory&lt;/a&gt; focused on Royal. Due to increasing activity and the complexity seen in attacks, organizations must place added emphasis on understanding the threat presented by Royal Ransomware.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Towards the end of 2022, &lt;a href="https://socradar.io/dark-web-profile-royal-ransomware/"&gt;researchers at SOCRadar&lt;/a&gt; recognized a relatively new cyber gang, Royal, as the most active ransomware threat. Attacks linked to Royal Ransomware have impacted a diverse pool of victims across many geographical regions and multiple industrial sectors, including healthcare and public healthcare , education, communications, and manufacturing, among others. Recently, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) released their &lt;a href="https://www.cisa.gov/sites/default/files/2023-03/aa23-061a-stopransomware-royal-ransomware.pdf"&gt;second joint advisory&lt;/a&gt; focused on Royal. Due to increasing activity and the complexity seen in attacks, organizations must place added emphasis on understanding the threat presented by Royal Ransomware.&lt;/p&gt; 
&lt;p&gt;Over the next few weeks, the NetWitness Threat Research team will be doing a deep dive into the threat actor group. For our first blog post in the series, we will provide an overview of the group/ransomware and touch on some of the key TTPs associated with this cyber gang. In Part 2, we will use NetWitness to analyze several samples of Royal Ransomware and highlight detection opportunities using the platform.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;Background and History&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;Royal Ransomware campaigns began in earnest in September 2022, although there is evidence of the group’s activity dating back as early as January 2022. There are two versions of the malware that have been spotted in attacks. The initial Royal Ransomware payloads were 64 bit Win32 executables written in C++(&lt;a href="https://www.hhs.gov/sites/default/files/royal-ransomware-analyst-note.pdf"&gt;i&lt;/a&gt;). Recently, Royal Ransomware added a Linux encryptor targeting VMware ESXi virtual machines(&lt;a href="https://twitter.com/BushidoToken/status/1621087221905514496?cxt=HHwWgIDTuamPof8sAAAA"&gt;ii&lt;/a&gt;). Artifacts discovered during post breach analysis, including use of specific encryptors and the form of previous ransom notes, suggest the Royal membership may be comprised of individuals with ties to the old Conti ransomware group(&lt;a href="https://twitter.com/VK_Intel/status/1557003350541242369"&gt;iii&lt;/a&gt;). The Royal Ransomware operators appear to be an unaffiliated financially motivated group, with ransom payment demands in the tens of millions USD.&lt;/p&gt; 
&lt;p&gt;Adding to their bona fides as a highly skilled cyber-crime operation, the Royal Ransomware group does not make use of the Ransomware-as-a-Service model, in which affiliates pay to distribute ransomware developed and maintained by another group. Instead, Royal functions as an independent group displaying a proficiency in targeting and penetrating large corporate environments without the use of Initial Access Brokers(i) (There are some indications that tracked group DEV-0569 has purchased access to networks to deliver Royal Ransomware(&lt;a href="https://www.blackberry.com/us/en/solutions/endpoint-security/ransomware-protection/royal-ransomware"&gt;iv&lt;/a&gt;)). In most Royal Ransomware attacks, access was gained using callback phishing, a social-engineering technique where victims contact a phone number included in an email and, after direct interaction with the attacker, are ultimately convinced to install malware masquerading as legitimate software. Other methods used to drop Royal Ransomware on victim systems include exploiting vulnerabilities on public facing applications, weaponizing business contact forms to spam companies with malicious links, placing bogus install files on popular file download sites, and, increasingly, malvertising via Google Ads.&lt;/p&gt; 
&lt;p&gt;Prior to encryption, the Royal Ransomware gang exfiltrates sensitive data from victim networks. It then uses the potential release of this information to entice companies to pay the ransom (a technique called double extortion). To put additional pressure on its' targets, the Royal group will drum up media coverage by using compromised Twitter accounts to contact journalists and news organizations and alert them to newly successful attacks.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;In the News&lt;/strong&gt;&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;u&gt;Nov-2022&lt;/u&gt;: Royal Ransomware operators posted evidence of breaching Silverstone Circuit, an English motor racing circuit and home of Formula One's British Grand Prix, to its leak site(&lt;a href="https://cybernews.com/news/silverstone-formula-one-ransomware/"&gt;v&lt;/a&gt;).&lt;/li&gt; 
 &lt;li&gt;&lt;u&gt;Dec-2022&lt;/u&gt;: In Travis County, Texas, the Travis County Appraisal District, responsible for assessing the appraisal values of all property in the county, attributed a successful ransomware attack to the Royal Ransomware threat group(&lt;a href="https://www.statesman.com/story/news/2022/12/05/travis-county-tx-home-appraisals-ransomware-attack/69703419007/"&gt;vi&lt;/a&gt;). The attack shut down phone lines, email access, and network connectivity for multiple days.&lt;/li&gt; 
 &lt;li&gt;&lt;u&gt;Dec-2022&lt;/u&gt;: American telecommunications company Intrado was added to the Royal Ransomware threat actors leak site(&lt;a href="https://www.bleepingcomputer.com/news/security/royal-ransomware-claims-attack-on-intrado-telecom-provider/"&gt;vii&lt;/a&gt;). The post alluded to the gang taking "internal documents \ passports \ employee driver's licenses" from Intrado's network. It is believed that the ransomware was responsible for a large outage in early December.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;&lt;strong&gt;Technical Summary&lt;/strong&gt;&lt;/h2&gt; 
&lt;h4&gt;&lt;em&gt;Windows Variant&lt;/em&gt;&lt;/h4&gt; 
&lt;p&gt;As discussed earlier, Royal Ransom group employs an assortment of methods to obtain initial access to target infrastructure. To begin its infection chain, Royal Ransomware accepts the following command line arguments(&lt;a href="https://www.cybereason.com/blog/royal-ransomware-analysis"&gt;viii)&lt;/a&gt;:&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;&lt;strong&gt;-id&lt;/strong&gt;&lt;/em&gt;: A 32-character alphanumeric value used to identify the compromised host. This argument is required and if omitted, prevents the ransomware from running.&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;&lt;strong&gt;-path&lt;/strong&gt;&lt;/em&gt;: Allows the operator to specify a path to be encrypted. This argument is not required when initiating the malware.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&lt;em&gt;-ep&lt;/em&gt;&lt;/strong&gt;: A number from between 0 and 100 representing the percentage of the file to be encrypted. If not specified, Royal will default to 50% encryption for files larger than 5.245 MB (Files smaller than 5.245 MB will be 100% encrypted). This argument is also optional and not required for successful execution.&lt;/p&gt; 
&lt;p&gt;Royal Ransomware operators use numerous legit open-source tools and Windows utilities to further entrench themselves in victim networks. The group has been observed using remote management software like AnyDesk and Atera Agent to maintain persistence(&lt;a href="https://www.kroll.com/en/insights/publications/cyber/royal-ransomware-deep-dive"&gt;ix&lt;/a&gt;). PowerSploit, a penetration testing framework made up of Powershell modules, allows Royal Ransomware threat actors to gain Administrator rights. Royal actors can achieve lateral movement via Microsoft Sysinternals' PsExec tool or discovered RDP credentials. The group can use NirCMD to stealthily run CMD commands directly on hosts machines. To discover domain members/groups, available network shares, and identify other network systems, Royal Ransomware attacks have utilized ADFind and Netscan from compromised domain controllers. As mentioned in the FBI/CISA Joint Cybersecurity Advisory, Royal operators have also used an SSH secured HTTP tunneling tool named Chisel to conduct C2 communication.&lt;/p&gt; 
&lt;p&gt;In addition to open-source tooling, groups distributing Royal have packaged the ransomware with other prominent malware families. In a few attacks, BATLOADER was used as the delivery mechanism Royal Ransomware payload(&lt;a href="https://www.microsoft.com/en-us/security/blog/2022/11/17/dev-0569-finds-new-ways-to-deliver-royal-ransomware-various-payloads/"&gt;x&lt;/a&gt;). The FBI has seen Ursnif/Gozi used to facilitate data exfiltration during Royal Ransomware attacks. Qakbot has also been found on systems preceding Royal ransom infections(&lt;a href="https://www.trendmicro.com/en_us/research/22/l/conti-team-one-splinter-group-resurfaces-as-royal-ransomware-wit.html"&gt;xi&lt;/a&gt;).&lt;/p&gt; 
&lt;p&gt;Prior to encrypting files and drives, Royal Ransomware takes several actions to hamper system defenses. If any encryption target files are in use by other processes, Royal will use Windows RestartManager to stop the desired applications/services. As is standard amongst many ransomware families, Royal attempts to prevent system recovery by using vssadmin Windows utility to silently delete all the available shadow copies. The malware can also disable antivirus using the system management tool Nsudo(&lt;a href="https://blog.polyswarm.io/royal-ransomware"&gt;xii&lt;/a&gt;).&lt;/p&gt; 
&lt;p&gt;Once the environment is staged and data has been retrieved, Royal Ransomware begins encryption. Royal uses multi-threaded encryption, a technique where the malicious payload accelerates time to encryption by launching multiple child processes(iv). This technique also makes stopping an ongoing ransomware attack more difficult. Earlier versions of Royal Ransomware borrowed its encryptors from BlackCat Ransomware. Over time, the threat group developed their own encryptor, Zeon, using the OpenSSL AES algorithm. A public key hardcoded in the malicious binary is used to encrypt both the private key and Initialization Vector. All encrypted files are appended with '&lt;em&gt;.royal&lt;/em&gt;' and a copy of the ransom note '&lt;em&gt;README.TXT&lt;/em&gt;' is placed in every directory containing encrypted data. The Royal ransom note, somewhat uniquely, does not contain any ransom demands, instead directing the victims to a TOR hosted chat application interface for further instructions.&lt;/p&gt; 
&lt;h4&gt;&lt;em&gt;Linux Variant&lt;/em&gt;&lt;/h4&gt; 
&lt;p&gt;Royal Ransomware's Linux variant seems to be early in its development. There are certain key differences from the Win32 version. For the Linux based version of Royal Ransomware targeting ESXi servers, the launch arguments are slightly different. While the &lt;em&gt;&lt;strong&gt;-id&lt;/strong&gt;&lt;/em&gt; argument is still required and the &lt;em&gt;&lt;strong&gt;-ep&lt;/strong&gt;&lt;/em&gt; can still be used to specify encryption percentage, the -path argument has been replaced by 4 other optional arguments(&lt;a href="https://www.trendmicro.com/en_us/research/23/b/royal-ransomware-expands-attacks-by-targeting-linux-esxi-servers.html"&gt;xiii&lt;/a&gt;):&amp;nbsp;&lt;em&gt;&lt;strong&gt;-stopvm&lt;/strong&gt;&lt;/em&gt; terminates VMs running on the target system with ESXCLI tool, &lt;em&gt;&lt;strong&gt;-fork&lt;/strong&gt;&lt;/em&gt; tells the ransomware to fork itself and move processing to the newly created child process, &lt;em&gt;&lt;strong&gt;-log&lt;/strong&gt;&lt;/em&gt; shows the logs of encrypted files, and a presently unimplemented &lt;em&gt;&lt;strong&gt;-vmonly&lt;/strong&gt;&lt;/em&gt; option. The Linux variant must still be executed from the command line; however the attacker must specify a target folder to ensure full encryption. Linux Royal does not set an exclusion list before encryption, but a searching function does exist as the malware recursively works its way through target directories preventing "double encryption,", or encryption of some core VM files ('&lt;em&gt;.sf&lt;/em&gt;', '&lt;em&gt;.v00&lt;/em&gt;', and '&lt;em&gt;.b00&lt;/em&gt;' extensions), encryption of the log file generated by the &lt;em&gt;&lt;strong&gt;-log&lt;/strong&gt;&lt;/em&gt; command line argument, and encryption of the ransom note. Based on Fortinet's analysis of a Linux based sample, this may indicate the "ransomware is executed either manually or by a dropper program that specifies which folders should be encrypted". Instead of '&lt;em&gt;.royal'&lt;/em&gt;&amp;nbsp;extension being appended to encrypted files, '&lt;em&gt;.royal_u&lt;/em&gt;' ('u' potentially designates a Unix system) postfix is used.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;Conclusion&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The Royal Ransomware group seems well suited to continue growing its list of victims for the foreseeable future. With several approaches to gain access to victim systems, employment of various anti-analysis and defense evasion tactics, ability to deliver and use different open-source tooling, and their usage of partial encryption via a proprietary encryptor, Royal operators can adapt attacks to get around even the best cyber defenses. The NetWitness Threat Research team’s investigation into this threat is ongoing and we will continue monitoring for any new developments. In the meantime, several pieces of content are currently available in NetWitness Live related to Royal Ransomware operations:&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;&lt;u&gt;Logs&lt;/u&gt;&lt;/em&gt;:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Nircmd for Command Execution (Logs)&lt;/strong&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Scheduled Tasks via schtasks.exe (Logs)&lt;/strong&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Stop/Kill Multiple Processes - NET.exe (Logs)&lt;/strong&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Stop/Kill Multiple Processes - SC.exe (Logs)&lt;/strong&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Stop/Kill Multiple Processes - TASKKILL.exe (Logs)&lt;/strong&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;u&gt;&lt;em&gt;Endpoint&lt;/em&gt;&lt;/u&gt;:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Deletes shadow volume copies&lt;/strong&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Nircmd for Command Execution (Endpoint)&lt;/strong&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;NSudo Trusted Installer from Command Line&lt;/strong&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Royal Ransomware Launch Arguments&lt;/strong&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Scheduled Tasks via schtasks.exe (Endpoint)&lt;/strong&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Stop/Kill Multiple Processes - NET.exe (Endpoint)&lt;/strong&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Stop/Kill Multiple Processes - SC.exe (Endpoint)&lt;/strong&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Stop/Kill Multiple Processes - TASKKILL.exe (Endpoint)&lt;/strong&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;In upcoming weeks, please be on the lookout for our follow-up Royal Ransomware post where we’ll investigate an attack with NetWitness.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;MITRE&lt;/strong&gt;&lt;/h2&gt; 
&lt;table width="100%"&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Technique&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Name&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Technique&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Name&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1"&gt;T1190&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Exploit Public Facing Application&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt; &lt;p&gt;T1083&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;File and Directory Discovery&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1"&gt;T1566&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Phishing&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;T1057&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Process Discovery&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1"&gt; &lt;p&gt;T1133&lt;/p&gt; &lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;External Remote Services&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;T1135&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Network Share Discovery&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1"&gt;T1105&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Ingress Tool Transfer&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;T1021.001&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Remote Desktop Protocol&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1"&gt;T1059&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Command and Scripting Interpreter&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;T1572&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Protocol Tunneling&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1"&gt;T1053.005&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Scheduled Task&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;T1486&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Data Encrypted for Impact&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1"&gt;T1569.002&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Service Execution&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;T1490&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Inhibit System Recovery&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td colspan="1" rowspan="1"&gt;T1562.001&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Disable or Modify Tools&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;T1489&lt;/td&gt; 
   &lt;td colspan="1" rowspan="1"&gt;Service Stop&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h2&gt;&lt;strong&gt;References&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;(i) - https://www.hhs.gov/sites/default/files/royal-ransomware-analyst-note.pdf&amp;nbsp;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;(ii) -&amp;nbsp;https://twitter.com/BushidoToken/status/1621087221905514496?cxt=HHwWgIDTuamPof8sAAAA&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;(iii) -&amp;nbsp;https://twitter.com/VK_Intel/status/1557003350541242369&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;(iv) -&amp;nbsp;https://www.blackberry.com/us/en/solutions/endpoint-security/ransomware-protection/royal-ransomware&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;(v) -&amp;nbsp;https://cybernews.com/news/silverstone-formula-one-ransomware/&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;(vi) -&amp;nbsp;https://www.statesman.com/story/news/2022/12/05/travis-county-tx-home-appraisals-ransomware-attack/69703419007/&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;(vii) -&amp;nbsp;https://www.bleepingcomputer.com/news/security/royal-ransomware-claims-attack-on-intrado-telecom-provider/&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;(viii) -&amp;nbsp;https://www.cybereason.com/blog/royal-ransomware-analysis&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;(ix) -&amp;nbsp;https://www.kroll.com/en/insights/publications/cyber/royal-ransomware-deep-dive&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;(x) -&amp;nbsp;https://www.microsoft.com/en-us/security/blog/2022/11/17/dev-0569-finds-new-ways-to-deliver-royal-ransomware-various-payloads/&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;(xi) -&amp;nbsp;https://www.trendmicro.com/en_us/research/22/l/conti-team-one-splinter-group-resurfaces-as-royal-ransomware-wit.html&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;(xii) -&amp;nbsp;https://blog.polyswarm.io/royal-ransomware&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;(xiii) -&amp;nbsp;https://www.trendmicro.com/en_us/research/23/b/royal-ransomware-expands-attacks-by-targeting-linux-esxi-servers.html&amp;nbsp;&amp;nbsp;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50269063&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmydev.netwitness.com%2Fnetwitness-security-llc-blog%2Fthreatprofileseries-anintroductiontoroyalransomware&amp;amp;bu=https%253A%252F%252Fmydev.netwitness.com%252Fnetwitness-security-llc-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 14 Mar 2023 04:00:00 GMT</pubDate>
      <guid>https://mydev.netwitness.com/netwitness-security-llc-blog/threatprofileseries-anintroductiontoroyalransomware</guid>
      <dc:date>2023-03-14T04:00:00Z</dc:date>
      <dc:creator>DarrenMccutchen</dc:creator>
    </item>
  </channel>
</rss>
