cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
mcn1k
Level 7
Report Inappropriate Content
Message 1 of 2

Endpoint Security Exper rule - match all events into single threat event..

Hi guys, 

 

I am writing a rule against a following TTP - https://attack.mitre.org/techniques/T1105/

Rule is working and being able to do report/block  as it should: 

 

Rule {
Process {
Include OBJECT_NAME {
-v "*certutil*"
}
Include PROCESS_CMD_LINE { -l "*-urlcache*" | -l "*-split*" | -l "*-f*" | -l "*-verifyctl*" | -l "*-encode*" | -l "*-decode" | -l "*-decodehex*"}
}
Target {
Match SECTION {
Include -access "CREATE"
}
}
}

 

Problem that I encounter is that is it is generating 2 many events for single activity. For example if you run certutil -f it will generate ~20 events since certutil is accessing many processes like netapi32.dll, ntdsapi.dll,  cabinet.dll etc. 

 

Question is how to combine (if possible) all events into single one within the rule. I guess there should be sort of "catch" but I can't find anything in the product guide or anywhere else.

 

Thank you in advance.

1 Reply
Tares1
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 2

Re: Endpoint Security Exper rule - match all events into single threat event..

Hello @mcn1k 

Thank you for reaching out to the support community.

The rule is working as expected generating events for each access of the certutil.exe process.

If you would limit it to a specific event for the process you could generate less events, but also miss legitimate events you would be trying to catch if it doesn't meet all the requirements in the rule.

You can generate more consolidated reports to try and have a better visualization for those events as well.

Hope this was helpful.

Was my reply helpful?
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!

Thanks and regards,
Tiago A
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community