Detecting CONTI CobaltStrike Lateral Movement Techniques - Part 1
Detection opportunities on lateral movement techniques used by CONTI ransomware group using CobaltStrike.
Introduction:
Definition:
Jump Module
Arch
Description
x86
x64
x86
x86
x64
Remote-Exec Module
Description
Simulation Setup
T1021.006 Remote Services: Windows Remote Management
A primer to WinRM
Windows Built-in WinRM tools
WinRS:




Invoke-Command & Enter-PSSession :



CobaltStrike jump winrm
EID
Action
Provider
Comment
6
WSMan Session Creation
Microsoft-Windows-WinRM
31
WSMan Session Creation
Microsoft-Windows-WinRM
3
Network Connection
Microsoft-Windows-Sysmon
EID
Action
Provider
Comment
1
WSMan Session Creation
Microsoft-Windows-Sysmon
3
WSMan Session Creation
Microsoft-Windows-Sysmon
17
Pipe Created
Microsoft-Windows-Sysmon
4656
Process Access
Microsoft-Windows-Security-Auditing
400
PowerShell Session Start
PowerShell
91
WSMan Session Creation
Microsoft-Windows-WinRM
31
WSMan Session Creation
Microsoft-Windows-WinRM
142
WSMan Operation Failure
Microsoft-Windows-WinRM



CobaltStrike jump winrm64


Evidence of Execution

Sigma Rules
Detection Validation
https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1021.006/T1021.006.md
DFIR

T1570 : Lateral Transfer Tool
CobaltStrike jump psexec & psexec64








EID
Action
Provider
Comment
5145
Network Share Access
Microsoft-Windows-Security-Auditing
7045
Service Creation
System
4697
Service Creation
Microsoft-Windows-Security-Auditing
1
Process Creation
Microsoft-Windows-Sysmon
1
Process Creation
Microsoft-Windows-Sysmon
13
Registry Value Set
Microsoft-Windows-Sysmon
CobaltStrike jump psexec_psh






EID
Action
Provider
Comment
5145
Network Share Access
Microsoft-Windows-Security-Auditing
7045
Service Creation
System
4697
Service Creation
Microsoft-Windows-Security-Auditing
17
Pipe Created
Microsoft-Windows-Sysmon
18
Pipe Connected
Microsoft-Windows-Sysmon
1
Process Creation
Microsoft-Windows-Sysmon
Sigma Rules
Detection Validation
https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1569.002/T1569.002.md
DFIR
https://github.com/SophosRapidResponse/CyberChef/blob/main/Cobalt%20Strike%20recipe%20for%20JABz.txt
Closing thoughts
PreviousDetecting Lateral Movement via Service Configuration ManagerNextDetecting CONTI CobaltStrike Lateral Movement Techniques - Part 2
Last updated