Many modern forms of malware are now file-less and rely on Command & Control (C2) infrastructure to assist outsiders with gaining unauthorized access to networks. This malware “phones home” to remote attackers, who then leverage the internal foothold to infiltrate networks and execute attacks. These attacks can be difficult to detect when security monitoring is limited to periodic vulnerability and compliance scans. Oftentimes these attacks execute against Windows OS based hosts using CMD and Powershell. These modern forms of malware do not rely on files present on a local disk where antivirus software can detect it. Once the malware is initiated, it persists in system memory and starts trying to create outbound connections to malicious domains. Domain generation algorithms (DGA) are used by the malware to generate domain names for use as potential rendezvous points on the public internet. From the outside of the network, an attacker aware of the pattern used by the DGA generates matching domains oftentimes purchased with stolen credit cards. Once a match is found between the malware and the outside attacker, an encrypted reverse TCP or SSH shell connection is made with the attacker.
The Challenges of Detecting Malware Leveraging C2 Infrastructure
Attacks leveraging Command and Control (C2) architecture with Domain Generation Algorithms (DGA) are effective for many reasons.- Firewalls do a great job of limiting uninitiated outside traffic. Few are configured to block connections from the inside going out.
- The ability to set up secure TCP and SSH connections is inherent in modern operating systems. The tools needed to perform the remote connection are easy to access once on the system.
- TLS Certificates are free and easy to get through services like Let’s Encrypt. This makes it possible to set up reverse HTTPS connections with ease.
- Law enforcement and authorities cannot keep up with the rapid pace that malicious domains can be established.
Ideas for Detecting Attacks Leveraging C2 Infrastructure
Monitor and Alert on Excessive Failed DNS Look-ups DNS is important for spotting command and control activity. As mentioned above, Domain Generation Algorithms (DGA) work to create random domain names on a cycle. The attacker knows what auto-generated domains will be generated and quickly register matching domains on the fly. This rapid registration process results in a whack-a-mole that law enforcement cannot keep up with. Attacks leveraging DGA will result in explosions of failed resolutions as malware tries them all. This makes tracking failed DNS lookups is a great way for Security Ops to identify malware. Enabled and Implement Event Logging for CMD and Powershell Security Operations teams should be monitoring CMD and Powershell activity. Unfortunately, event logging for both CMD and Powershell activity are not enabled in Windows by default. Microsoft first made full Powershell event logging is available in version 5.1 which was bundled with Window 10 anniversary edition. If your shop is still a few versions behind, be warned that Windows 7 ships with Powershell version 2 out of the box. Be sure your organization is running an up to date version of Powershell and enable security event logging for both it and CMD. You can implement event logging for both CMD and Powershell via Group Policy Objects (GPO). Check out a few references below for more information.- https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/component-updates/command-line-process-auditing
- https://sid-500.com/2017/08/16/monitoring-windows-powershell-enable-module-logging/
- https://blogs.technet.microsoft.com/nathangau/2017/05/24/security-monitoring-mp-powershell-exploit-toolkit-rules/
Ideas for Preventing Attacks Leveraging C2 Infrastructure
Enable Application and Process Whitelisting Enabling application whitelisting utilities on endpoints is an effective mitigation. There are no shortage of solutions, but if you are running a modern Active Directory domain, you already have one. Microsoft's Applocker can prevent Powershell from running and is included with current versions of Windows Server. Deploy an End Point Security Utility with Advanced Functionality Basic (and free) antivirus utilities are all but useless. Install an endpoint security utility that includes host-based firewall and intrusion detection capabilities. An effective utility will detect malicious activity and protocols and stop them automatically. Hopefully this post will have you on your way to enhancing your security operations monitoring. Please share comments, corrections and other ideas in the comments.
Christian Hyatt
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)