• DMCA
  • Disclaimer
  • Terms and Conditions
  • Cookie Privacy Policy
  • Privacy Policy
  • Contact
  • Advertise
  • Home
  • Review
    Spotify starts selling live music tickets to fans directly – TechCrunch

    Spotify starts selling live music tickets to fans directly – TechCrunch

    With a €43M EU grant and €1.2M from a VC, this startup plans to turn CO2 emissions into gold – TechCrunch

    With a €43M EU grant and €1.2M from a VC, this startup plans to turn CO2 emissions into gold – TechCrunch

    South Africa’s DataProphet closes M to scale its AI-as-a-service platform for manufacturers – TechCrunch

    South Africa’s DataProphet closes $10M to scale its AI-as-a-service platform for manufacturers – TechCrunch

    Egyptian startup Convertedin raises M, caters to e-commerce brands in MENA and Latin America – TechCrunch

    Egyptian startup Convertedin raises $3M, caters to e-commerce brands in MENA and Latin America – TechCrunch

    Elon Musk sells nearly  billion in Tesla shares – TechCrunch

    Elon Musk sells nearly $7 billion in Tesla shares – TechCrunch

    The DOJ is reportedly prepping an antitrust suit against Google over its ad business – TechCrunch

    The DOJ is reportedly prepping an antitrust suit against Google over its ad business – TechCrunch

  • Gaming
    Here’s How The Summer Box Office Compares To Pre-Pandemic Numbers

    Here’s How The Summer Box Office Compares To Pre-Pandemic Numbers

    Never Have I Ever season 3 review: A penultimate season racing to the end

    Never Have I Ever season 3 review: A penultimate season racing to the end

    Super Punch-Out’s Secret Two-Player Mode Discovered After 28 Years

    Super Punch-Out’s Secret Two-Player Mode Discovered After 28 Years

    Temtem Shows Off Version 1.0 Features, Launching On Switch Next Month

    Temtem Shows Off Version 1.0 Features, Launching On Switch Next Month

    Japanese Pixel Art Adventure Tokyo Stories Looks Very Cool

    Japanese Pixel Art Adventure Tokyo Stories Looks Very Cool

    Sonic Frontiers World Premiere Coming To Gamescom Opening Night Live

    Sonic Frontiers World Premiere Coming To Gamescom Opening Night Live

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    Motorola reveals the price of the Moto Razr 2022 a day ahead of the launch

    Motorola reveals the price of the Moto Razr 2022 a day ahead of the launch

    Alpha Tracks August 22 Chart

    Alpha Tracks August 22 Chart

    AXPONA 2022 Show Report: Back to Listening in Person

    AXPONA 2022 Show Report: Back to Listening in Person

    Last chance to reserve the new Galaxy Fold, Flip, and Watch devices and score up to 0 in credit

    Last chance to reserve the new Galaxy Fold, Flip, and Watch devices and score up to $200 in credit

    Blackmagic Design Price Increases – Newsshooter

    Blackmagic Design Price Increases – Newsshooter

    Lenovo Legion Y70 set to launch on August 18

    Lenovo Legion Y70 set to launch on August 18

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers
    AORUS Z690i Ultra Plus, Now With Less WHEA Errors

    AORUS Z690i Ultra Plus, Now With Less WHEA Errors

    NVIDIA’s Preliminary Earnings Are Not Pretty

    NVIDIA’s Preliminary Earnings Are Not Pretty

    Fractal Design Define 7 Nano, For The ITX Lover

    Fractal Design Define 7 Nano, For The ITX Lover

    Oh Ya, Netflix Did Get Into Games

    Oh Ya, Netflix Did Get Into Games

    Workstream – Monoprice’s Heavy Duty Gas Spring Desk Mount For A Single 32″ To 49″ Monitor

    Workstream – Monoprice’s Heavy Duty Gas Spring Desk Mount For A Single 32″ To 49″ Monitor

    Podcast #688 – Intel & AMD Financials, Ryzen 7000 Date, be quiet! Pure Base 500 FX, Sonos, 0-Day Hacks + MORE!

    Podcast #688 – Intel & AMD Financials, Ryzen 7000 Date, be quiet! Pure Base 500 FX, Sonos, 0-Day Hacks + MORE!

  • Applications
    CISA Issues Warning on Active Exploitation of UnRAR Software for Linux Systems

    CISA Issues Warning on Active Exploitation of UnRAR Software for Linux Systems

    Microsoft Issues Patches for 121 Flaws, Including Zero-Day Under Active Attack

    Microsoft Issues Patches for 121 Flaws, Including Zero-Day Under Active Attack

    Fitbit to remove PC syncing option for its wearables, music transfers are going away too

    Fitbit to remove PC syncing option for its wearables, music transfers are going away too

    Spotify launches new Home experience for Android users, iOS gets it too

    Spotify launches new Home experience for Android users, iOS gets it too

    Apple hosts world premiere event for Five Days at Memorial ahead of Friday’s debut

    Apple hosts world premiere event for Five Days at Memorial ahead of Friday’s debut

    50 free TV channels are coming to Google TV; no downloading or subscriptions will be required

    50 free TV channels are coming to Google TV; no downloading or subscriptions will be required

  • Security
    Predator Pleads Guilty After Targeting Thousands of Young Girls Online

    Predator Pleads Guilty After Targeting Thousands of Young Girls Online

    Are cloud containers a sugar-coated threat?

    Are cloud containers a sugar-coated threat?

    Surge in CVEs as Microsoft Fixes Exploited Zero Day Bugs

    Surge in CVEs as Microsoft Fixes Exploited Zero Day Bugs

    Software Development Pipelines Offer Cybercriminals ‘Free-Range’ Access to Cloud, On-Prem

    Software Development Pipelines Offer Cybercriminals ‘Free-Range’ Access to Cloud, On-Prem

    Microsoft Patches Zero-Day Actively Exploited in the Wild

    Microsoft Patches Zero-Day Actively Exploited in the Wild

    Halo Security Emerges From Stealth With Full Attack Surface Management Platform

    Halo Security Emerges From Stealth With Full Attack Surface Management Platform

No Result
View All Result
  • Home
  • Review
    Spotify starts selling live music tickets to fans directly – TechCrunch

    Spotify starts selling live music tickets to fans directly – TechCrunch

    With a €43M EU grant and €1.2M from a VC, this startup plans to turn CO2 emissions into gold – TechCrunch

    With a €43M EU grant and €1.2M from a VC, this startup plans to turn CO2 emissions into gold – TechCrunch

    South Africa’s DataProphet closes M to scale its AI-as-a-service platform for manufacturers – TechCrunch

    South Africa’s DataProphet closes $10M to scale its AI-as-a-service platform for manufacturers – TechCrunch

    Egyptian startup Convertedin raises M, caters to e-commerce brands in MENA and Latin America – TechCrunch

    Egyptian startup Convertedin raises $3M, caters to e-commerce brands in MENA and Latin America – TechCrunch

    Elon Musk sells nearly  billion in Tesla shares – TechCrunch

    Elon Musk sells nearly $7 billion in Tesla shares – TechCrunch

    The DOJ is reportedly prepping an antitrust suit against Google over its ad business – TechCrunch

    The DOJ is reportedly prepping an antitrust suit against Google over its ad business – TechCrunch

  • Gaming
    Here’s How The Summer Box Office Compares To Pre-Pandemic Numbers

    Here’s How The Summer Box Office Compares To Pre-Pandemic Numbers

    Never Have I Ever season 3 review: A penultimate season racing to the end

    Never Have I Ever season 3 review: A penultimate season racing to the end

    Super Punch-Out’s Secret Two-Player Mode Discovered After 28 Years

    Super Punch-Out’s Secret Two-Player Mode Discovered After 28 Years

    Temtem Shows Off Version 1.0 Features, Launching On Switch Next Month

    Temtem Shows Off Version 1.0 Features, Launching On Switch Next Month

    Japanese Pixel Art Adventure Tokyo Stories Looks Very Cool

    Japanese Pixel Art Adventure Tokyo Stories Looks Very Cool

    Sonic Frontiers World Premiere Coming To Gamescom Opening Night Live

    Sonic Frontiers World Premiere Coming To Gamescom Opening Night Live

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    Motorola reveals the price of the Moto Razr 2022 a day ahead of the launch

    Motorola reveals the price of the Moto Razr 2022 a day ahead of the launch

    Alpha Tracks August 22 Chart

    Alpha Tracks August 22 Chart

    AXPONA 2022 Show Report: Back to Listening in Person

    AXPONA 2022 Show Report: Back to Listening in Person

    Last chance to reserve the new Galaxy Fold, Flip, and Watch devices and score up to 0 in credit

    Last chance to reserve the new Galaxy Fold, Flip, and Watch devices and score up to $200 in credit

    Blackmagic Design Price Increases – Newsshooter

    Blackmagic Design Price Increases – Newsshooter

    Lenovo Legion Y70 set to launch on August 18

    Lenovo Legion Y70 set to launch on August 18

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers
    AORUS Z690i Ultra Plus, Now With Less WHEA Errors

    AORUS Z690i Ultra Plus, Now With Less WHEA Errors

    NVIDIA’s Preliminary Earnings Are Not Pretty

    NVIDIA’s Preliminary Earnings Are Not Pretty

    Fractal Design Define 7 Nano, For The ITX Lover

    Fractal Design Define 7 Nano, For The ITX Lover

    Oh Ya, Netflix Did Get Into Games

    Oh Ya, Netflix Did Get Into Games

    Workstream – Monoprice’s Heavy Duty Gas Spring Desk Mount For A Single 32″ To 49″ Monitor

    Workstream – Monoprice’s Heavy Duty Gas Spring Desk Mount For A Single 32″ To 49″ Monitor

    Podcast #688 – Intel & AMD Financials, Ryzen 7000 Date, be quiet! Pure Base 500 FX, Sonos, 0-Day Hacks + MORE!

    Podcast #688 – Intel & AMD Financials, Ryzen 7000 Date, be quiet! Pure Base 500 FX, Sonos, 0-Day Hacks + MORE!

  • Applications
    CISA Issues Warning on Active Exploitation of UnRAR Software for Linux Systems

    CISA Issues Warning on Active Exploitation of UnRAR Software for Linux Systems

    Microsoft Issues Patches for 121 Flaws, Including Zero-Day Under Active Attack

    Microsoft Issues Patches for 121 Flaws, Including Zero-Day Under Active Attack

    Fitbit to remove PC syncing option for its wearables, music transfers are going away too

    Fitbit to remove PC syncing option for its wearables, music transfers are going away too

    Spotify launches new Home experience for Android users, iOS gets it too

    Spotify launches new Home experience for Android users, iOS gets it too

    Apple hosts world premiere event for Five Days at Memorial ahead of Friday’s debut

    Apple hosts world premiere event for Five Days at Memorial ahead of Friday’s debut

    50 free TV channels are coming to Google TV; no downloading or subscriptions will be required

    50 free TV channels are coming to Google TV; no downloading or subscriptions will be required

  • Security
    Predator Pleads Guilty After Targeting Thousands of Young Girls Online

    Predator Pleads Guilty After Targeting Thousands of Young Girls Online

    Are cloud containers a sugar-coated threat?

    Are cloud containers a sugar-coated threat?

    Surge in CVEs as Microsoft Fixes Exploited Zero Day Bugs

    Surge in CVEs as Microsoft Fixes Exploited Zero Day Bugs

    Software Development Pipelines Offer Cybercriminals ‘Free-Range’ Access to Cloud, On-Prem

    Software Development Pipelines Offer Cybercriminals ‘Free-Range’ Access to Cloud, On-Prem

    Microsoft Patches Zero-Day Actively Exploited in the Wild

    Microsoft Patches Zero-Day Actively Exploited in the Wild

    Halo Security Emerges From Stealth With Full Attack Surface Management Platform

    Halo Security Emerges From Stealth With Full Attack Surface Management Platform

No Result
View All Result
No Result
View All Result
Home Security

Stories from the SOC – Detecting internal reconnaissance

RealHacker Staff by RealHacker Staff
June 27, 2022
Stories from the SOC – Detecting internal reconnaissance
Share on FacebookShare on Twitter


Stories from the SOC is a blog series that describes recent real-world security incident investigations conducted and reported by the AT&T SOC analyst team for AT&T Managed Extended Detection and Response customers.

Executive summary

Internal Reconnaissance, step one of the Cyber Kill Chain, is the process of collecting internal information about a target network to identify vulnerabilities that can potentially be exploited.  Threat actors use the information gained from this activity to decide the most effective way to compromise the target network. Vulnerable services can be exploited by threat actors and potentially lead to a network breach. A network breach puts the company in the hands of cybercriminals. This can lead to ransomware attacks costing the company millions of dollars to remediate along with a tarnished public image. 

The Managed Extended Detection and Response (MXDR) analyst team received two alarms regarding an asset performing network scans within a customer’s environment. Further investigation into these alarms revealed that the source asset was able to scan 60 unique IPs within the environment and successfully detected numerous open ports with known vulnerabilities.

Investigation

Initial alarm review

Indicators of Compromise (IOC)

The initial alarm that prompted this investigation was a Darktrace Cyber Intelligence Platform event that was ingested by USM Anywhere. The priority level associated with this alarm was High, one level below the maximum priority of Critical.  Network scanning is often one of the first steps a threat actor takes when attempting to compromise a network, so it is a red flag any time an unknown device is scanning the network without permission. From here, the SOC went deeper into associated events to see what activity was taking place in the customer’s environment. The image shown below is the Darktrace alarm that initiated the investigation.

Darktrace alarm

Expanded investigation

Events search

Utilizing the filters built into USM Anywhere , the events were narrowed down to the specific source asset IP address and Host Name to only query events associated to that specific asset. The following events were found that provide more information about the reconnaissance activity that was being observed.

Recon activity 1

recon activity 2

Event deep dive

Upon reviewing the logs from the events shown above, the SOC was able to determine that the source asset scanned two separate Classless Inter-Domain Routing (CIDR) blocks, detecting, and scanning 60 unique internal devices for open ports. As shown in the log snippets below, the scans revealed multiple open ports with known vulnerabilities, most notable is Server Message Block (SMB) port 445 which is the key attack vector for the infamous WannaCry malware. Looking at the logs we can also see that the source asset detected port 5985, the port utilized by Windows Remote Management (WinRM). WinRM can be used by threat actors to move laterally in environments by executing remote commands on other assets from the compromised host. These remote commands are typically batch files performing malicious activity or implanting backdoors to maintain persistence in the network.  Lastly, we can see the asset scanning for Lightweight Directory Access Protocol (LDAP) port 389. LDAP traffic, if not encrypted properly, can be sniffed with Wireshark and potentially expose sensitive information such as usernames and passwords.

event deep dive

Reviewing for additional indicators

After the initial analysis of the source asset, we pivoted our event search to include assets within the target IP ranges. Using the filters in USM Anywhere, the SOC was able to search the events in the customers environment for the targeted IP addresses and analyze all events searching for any anomalous activity that would indicate a breach took place. Further review into the customer’s network did not reveal any additional activity following the scanning. The SOC was unable to find any evidence that the threat actor advanced from reconnaissance to weaponization, or further up in the kill chain. This suggests that the activity is isolated for the time being.

Response

Building the investigation

Due to the nature of reconnaissance scanning, this could potentially be a threat actor attempting to discover vulnerable services on assets within the environment. The customer was advised to quarantine the asset off the network and investigate the source of the scanning activity to determine if a compromise took place. It was recommended to run a full Antivirus scan on the asset to ensure that this activity was not related to malware attempting to move laterally in their environment.

Customer interaction

The customer was notified via phone call as defined in their Incident Response Plan (IRP). The customer was able to isolate the asset off the network to prevent any additional network scans. They then began to investigate the asset by performing a software inventory of the machine to determine the source of the network scanning and reviewing the Windows Event Viewer logs to determine the user account associated with the scanning activity. The quick response of the MXDR team allowed the customer to investigate the asset before any additional actions took place as a result of the initial network scans that triggered the alarms.



Source link

Related

Tags: detectingInternalreconnaissanceSoCStories
RealHacker Staff

RealHacker Staff

Recent Posts

  • My Forever Studio S4 Ep12: Shadow Child won’t take a CS-80
  • Predator Pleads Guilty After Targeting Thousands of Young Girls Online
  • Motorola reveals the price of the Moto Razr 2022 a day ahead of the launch
  • Are cloud containers a sugar-coated threat?
  • Spotify starts selling live music tickets to fans directly – TechCrunch
  • Alpha Tracks August 22 Chart
  • AXPONA 2022 Show Report: Back to Listening in Person
  • Surge in CVEs as Microsoft Fixes Exploited Zero Day Bugs

Follow Us

Categories

  • Applications
  • Audio
  • Camera
  • Computers
  • Gaming
  • Gear
  • Laptop
  • Metaverse
  • Microsoft
  • Photography
  • Review
  • Security
  • Smartphone
  • Uncategorized

Recent News

Predator Pleads Guilty After Targeting Thousands of Young Girls Online

Predator Pleads Guilty After Targeting Thousands of Young Girls Online

August 10, 2022
Motorola reveals the price of the Moto Razr 2022 a day ahead of the launch

Motorola reveals the price of the Moto Razr 2022 a day ahead of the launch

August 10, 2022
  • DMCA
  • Disclaimer
  • Terms and Conditions
  • Cookie Privacy Policy
  • Privacy Policy
  • Contact
  • Advertise

© 2019 - theme develop by real hacker news.

No Result
View All Result
  • Home
  • Review
  • Gaming
  • Gear
  • Computers
  • Applications
  • Security

© 2019 - theme develop by real hacker news.

error: Content is protected !!