Detection rules › Elastic

Potential Evasion via Windows Filtering Platform

Author
Elastic
Source
upstream

Identifies multiple Windows Filtering Platform block events and where the process name is related to an endpoint security software. Adversaries may add malicious WFP rules to prevent Endpoint security from sending telemetry.

MITRE ATT&CK coverage

TacticTechniques
Defense EvasionT1562 Impair Defenses, T1562.001 Impair Defenses: Disable or Modify Tools, T1562.004 Impair Defenses: Disable or Modify System Firewall

Event coverage

ProviderEvent IDTitle
Security-Auditing5152The Windows Filtering Platform blocked a packet.
Security-Auditing5157The Windows Filtering Platform has blocked a connection.

Stages and Predicates

Stage 1: eql:network

event.action:"windows-firewall-packet-block" and process.name:"bdagent.exe"

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
event.actionwildcard
  • windows-firewall-packet-block
  • windows-firewall-packet-drop
process.namewildcard
  • ALMon.exe
  • ALUpdate.exe
  • ALsvc.exe
  • AosUImanager.exe
  • BDSubWiz.exe
  • CSFalconController.exe
  • CSFalconService.exe
  • CarbonBlackClientSetup.exe
  • Clnrbin.exe
  • Coreinst.exe
  • CrAmTray.exe
  • CybereasonRansomFreeServiceHost.exe
  • CybereasonSensor.exe
  • CylanceProtectSetup.exe
  • CylanceUI.exe
  • EHttpSrv.exe
  • EPCUserAvatar.exe
  • ESConfigTool.exe
  • FCConfig.exe
  • FCVbltScan.exe
  • FSAEConfig.exe
  • FSSOMA.exe
  • FWInstCheck.exe
  • ForceUpdateAlongSideSGN.exe
  • FortiAvatar.exe
  • FortiClient.exe
  • FortiClient_Diagnostic_Tool.exe
  • FortiESNAC.exe
  • FortiSSLVPNdaemon.exe
  • FwWindowsFirewallHandler.exe
  • InstWrap.exe
  • MBAMHelper.exe
  • MSASCui.exe
  • MSASCuiL.exe
  • MarSetup.exe
  • McAPExe.exe
  • McChHost.exe
  • McPvTray.exe
  • McpService.exe
  • McsAgent.exe
  • McsClient.exe
  • McsHeartbeat.exe
  • MfeEpeSvc.exe
  • MsSense.exe
  • N360Downloader.exe
  • NTRTScan.exe
  • Notifier.exe
  • ProductAgentService.exe
  • ProductAgentUI.exe
  • ProtectedModuleHost.exe
  • PwmSvc.exe
  • QualysAgentUI.exe
  • QualysProxy.exe
  • SAA.exe
  • SAVAdminService.exe
  • SAVCleanupService.exe
  • SCFManager.exe
  • SCFService.exe
  • SCTBootTasks.exe
  • SCTCleanupService.exe
  • SUMService.exe
  • SVRTcli.exe
  • SVRTgui.exe
  • SVRTservice.exe
  • SavMain.exe
  • SavProgress.exe
  • SavProxy.exe
  • SavService.exe
  • SenseSampleUploader.exe
  • SfCtlCom.exe
  • SophosAlert.exe
  • SophosUpdate.exe
  • TMAS_OL.exe
  • TMAS_OLImp.exe
  • TMAS_OLSentry.exe
  • TrGUI.exe
  • TracCAPI.exe
  • TracSrvWrapper.exe
  • WatchDog.exe
  • WscAVExe.exe
  • av_task.exe
  • avp.exe
  • avpsus.exe
  • avpui.exe
  • bdagent.exe
  • bdreinit.exe
  • cabarc.exe
  • cb.exe
  • ccsvchst.exe
  • collectoragent.exe
  • coreServiceShell.exe
  • cpmsi_tool.exe
  • csfalconcontainer.exe
  • cylancesvc.exe
  • cyupdate.exe
  • ds_agent.exe
  • dsa.exe
  • ecls.exe
  • ecmd.exe
  • ecomserver.exe
  • eeclnt.exe
  • egui.exe
  • eh64.exe
  • ekrn.exe
  • elastic-agent.exe
  • elastic-endpoint.exe
  • emu-cci.exe
  • emu-gui.exe
  • emu-rep.exe
  • emu-uninstall.exe
  • emu_install.exe
  • epefprtrainer.exe
  • esensor.exe
  • fcappdb.exe
  • fcasc.exe
  • fcauth.exe
  • fccomint.exe
  • fcdblog.exe
  • fchelper.exe
  • fclanguageselector.exe
  • fcmgr.exe
  • fcreg.exe
  • fcwizard.exe
  • fcwsc.exe
  • fcwscd7.exe
  • fmon.exe
  • forticlient.exe
  • fortifw.exe
  • fortiproxy.exe
  • fortiscand.exe
  • fortitray.exe
  • fortivpnst.exe
  • fortiwad.exe
  • fortiwadbd.exe
  • fortiwf.exe
  • fwinfo.exe
  • ipsec.exe
  • isPwdSvc.exe
  • kl_platf.exe
  • klnagent.exe
  • klnagwds.exe
  • klnsacwsrv.exe
  • lc_sensor.exe
  • macmnsvc.exe
  • masvc.exe
  • mbae-setup.exe
  • mbae-svc.exe
  • mbae-uninstaller.exe
  • mbae.exe
  • mbae64.exe
  • mbaeLoader32.exe
  • mbaeloader64.exe
  • mbam-dor.exe
  • mbamgui.exe
  • mbampt.exe
  • mbamscheduler.exe
  • mbamservice.exe
  • mbamtrayctrl.exe
  • mcods.exe
  • mcshield.exe
  • mctray.exe
  • mcuicnt.exe
  • mcuihost.exe
  • mcupdate.exe
  • mfeProvisionModeUtility.exe
  • mfecanary.exe
  • mfeesp.exe
  • mfeffcoreservice.exe
  • mfefire.exe
  • mfefw.exe
  • mfehidin.exe
  • mfemms.exe
  • mfetp.exe
  • mfevtps.exe
  • mfewc.exe
  • mfewch.exe
  • mfewcui.exe
  • minionhost.exe
  • minodlogin.exe
  • mmsinfo.exe
  • msmpeng.exe
  • msmpsvc.exe
  • native.exe
  • ndep.exe
  • nss.exe
  • ntrmv.exe
  • osCheck.exe
  • p95tray.exe
  • pccntmon.exe
  • pdiface.exe
  • pdscan.exe
  • pwmConsole.exe
  • qualysagent.exe
  • rmon.exe
  • rphcp.exe
  • sargui.exe
  • sav32cli.exe
  • sensecncproxy.exe
  • sentinelone.exe
  • smc.exe
  • sntpservice.exe
  • spa.exe
  • spike.exe
  • splunk.exe
  • ssp.exe
  • stpass.exe
  • submitv.exe
  • swc_service.exe
  • swi_di.exe
  • swi_filter.exe
  • swi_service.exe
  • symbos.exe
  • symcorpui.exe
  • sysmon.exe
  • sysmon64.exe
  • taniumclient.exe
  • tda.exe
  • tmccsf.exe
  • trac.exe
  • ufnavi.exe
  • uninstalldcagent.exe
  • vizorhtmldialog.exe
  • vna_install64.exe
  • vna_utils.exe
  • vsmon.exe
  • vtpinfo.exe
  • windefend.exe
  • xagt.exe
  • xagtnotif.exe
  • xtray.exe