RPC Firewall Detection for Remote MS-EFSR Encrypting File System Abuse
Alerts on RPC Firewall events targeting MS-EFSR interface UUIDs associated with remote encrypting file system abuse.
FreeUnreviewedSigmahighv1
rpc-firewall-detection-for-remote-ms-efsr-encrypting-file-system-abuse-5f92fff9
title: RPC Firewall Detection for Remote MS-EFSR Encrypting File System Abuse
id: 32f246d3-582e-4ef7-8d52-a172f3dc9104
status: test
description: This rule flags RPC Firewall events (EventLog RPCFW, EventID 3) for requests to the MS-EFSR-related interface UUIDs. Attackers can use MS-EFSR encryption capabilities over remote RPC to support data encryption or related post-compromise activity, making targeted remote calls an important signal. It relies on RPC Firewall telemetry including the interface UUIDs observed in the logged blocked/controlled RPC traffic.
references:
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36942
- https://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-EFSR.md
- https://github.com/zeronetworks/rpcfirewall
- https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/rpc_firewall/rpc_firewall_efs_abuse.yml
author: Sagie Dulce, Dekel Paz, Huntrule Team
date: 2022-01-01
tags:
- attack.lateral-movement
logsource:
product: rpc_firewall
category: application
definition: 'Requirements: install and apply the RPC Firewall to all processes with "audit:true action:block uuid:df1941c5-fe89-4e79-bf10-463657acf44d or c681d488-d850-11d0-8c52-00c04fd90f7e'
detection:
selection:
EventLog: RPCFW
EventID: 3
InterfaceUuid:
- df1941c5-fe89-4e79-bf10-463657acf44d
- c681d488-d850-11d0-8c52-00c04fd90f7e
condition: selection
falsepositives:
- Legitimate usage of remote file encryption
level: high
license: DRL-1.1
related:
- id: 5f92fff9-82e2-48eb-8fc1-8b133556a551
type: derived
What it detects
This rule flags RPC Firewall events (EventLog RPCFW, EventID 3) for requests to the MS-EFSR-related interface UUIDs. Attackers can use MS-EFSR encryption capabilities over remote RPC to support data encryption or related post-compromise activity, making targeted remote calls an important signal. It relies on RPC Firewall telemetry including the interface UUIDs observed in the logged blocked/controlled RPC traffic.
Known false positives
- Legitimate usage of remote file encryption
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.