HomeSecurityMicrosoft Sysmon: Detects malware breach attempts

Microsoft Sysmon: Detects malware intrusion attempts

Sysmon 13, released by Microsoft has a new security feature that detects whether a process has been affected by malware.

Sysmon

One of the techniques hackers use is to inject malicious code into a legitimate Windows process to avoid detection. This tactic allows the malware to run, but Task Manager detects it as a standard Windows process running in the background.

Hollowing technique starts with a legitimate process in a suspended state, which then replaces the legitimate code with malicious code . This malicious code is then executed by the process, with whatever privileges are granted to the process.

Herpaderping is a more advanced technique where malware modifies its disk image to look like legitimate software after the malware is loaded. When security software scans the file on disk, it will see a harmless file while the malicious code is executing in memory .

Many well-known malware use similar techniques to evade detection, including Mailto/defray777 ransomware, TrickBot , and BazarBackdoor.

malware

If you're not familiar with Sysmon or System Monitor, it's a tool from Sysinternals designed to monitor systems for malicious activity and record those events in the Windows event log.

You can download Sysmon from the Sysinternals page or https://live.sysinternals.com/sysmon.exe.

To enable tamper detection, administrators must add the "ProcessTampering" configuration option to a configuration file. Sysmon will simply monitor basic events such as process creation and file time changes without a configuration file.

This new directive has been added to Sysmon 4.50, which can be viewed by running the sysmon -s command.

Once launched, the program will install the driver and begin collecting data silently in the background.

All Sysmon events will be logged in "Applications and Services Logs/Microsoft/Windows/Sysmon/Operational" in Event Viewer.

With the ProcessTampering feature enabled, when a Hollowing process or herpaderping process is detected, Sysmon will create an “Event 25 – Process Tampering” entry in the Event Viewer.

To learn more about Sysmon, visit the Sysinternals and try out the various configuration options it offers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS