RPC Firewall Detection for Remote MS-EFSR Encrypting File System Abuse

Alerts on RPC Firewall events targeting MS-EFSR interface UUIDs associated with remote encrypting file system abuse.

FreeUnreviewedSigmahighv1
title: RPC Firewall Detection for Remote MS-EFSR Encrypting File System Abuse
id: 32f246d3-582e-4ef7-8d52-a172f3dc9104
status: test
description: This rule flags RPC Firewall events (EventLog RPCFW, EventID 3) for requests to the MS-EFSR-related interface UUIDs. Attackers can use MS-EFSR encryption capabilities over remote RPC to support data encryption or related post-compromise activity, making targeted remote calls an important signal. It relies on RPC Firewall telemetry including the interface UUIDs observed in the logged blocked/controlled RPC traffic.
references:
  - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36942
  - https://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-EFSR.md
  - https://github.com/zeronetworks/rpcfirewall
  - https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/application/rpc_firewall/rpc_firewall_efs_abuse.yml
author: Sagie Dulce, Dekel Paz, Huntrule Team
date: 2022-01-01
tags:
  - attack.lateral-movement
logsource:
  product: rpc_firewall
  category: application
  definition: 'Requirements: install and apply the RPC Firewall to all processes with "audit:true action:block uuid:df1941c5-fe89-4e79-bf10-463657acf44d or c681d488-d850-11d0-8c52-00c04fd90f7e'
detection:
  selection:
    EventLog: RPCFW
    EventID: 3
    InterfaceUuid:
      - df1941c5-fe89-4e79-bf10-463657acf44d
      - c681d488-d850-11d0-8c52-00c04fd90f7e
  condition: selection
falsepositives:
  - Legitimate usage of remote file encryption
level: high
license: DRL-1.1
related:
  - id: 5f92fff9-82e2-48eb-8fc1-8b133556a551
    type: derived

What it detects

This rule flags RPC Firewall events (EventLog RPCFW, EventID 3) for requests to the MS-EFSR-related interface UUIDs. Attackers can use MS-EFSR encryption capabilities over remote RPC to support data encryption or related post-compromise activity, making targeted remote calls an important signal. It relies on RPC Firewall telemetry including the interface UUIDs observed in the logged blocked/controlled RPC traffic.

Known false positives

  • Legitimate usage of remote file encryption

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.