elastic / elastic/detection-rules

[Meta] Adversary Behavior Detections - Midnight Blizzard (APT29)

Open
#3,412 0 comments 1 reaction 1 assignee Claimed by @terrancedejesus View on GitHub
backlog Domain: Cloud Workloads Integration: Azure Meta Team: TRADE
Dominant language
Python
Stars
2.7k
Forks
696
Avg merge
4d 17h
Merged PRs (30d)
87

Description

## Parent Epic (If Applicable)

## Meta Summary
This meta has been created to capture research and analysis on recent public intelligence from Microsoft on Midnight Blizzard (aka APT29). Referenced below, several TTPs have been analyzed and released that detail abusing native Azure services such as Graph, authorization and authentication workflows with OAuth, entity accounts in Entra ID and much more.

The goal of this meta should be to assess the existing intelligence shared and publicly related information enough to setup proper infrastructure, conduct emulation and identify candid SIEM detection rule capabilities.

This may rely on integrations such as Azure and O365 for log ingestion and visibility.

## Estimated Time to Complete
~2 sprint cycles (4 weeks)

## Potential Blockers
No initial blockers but this may be subject to change as we explore.

## Tasklist

```[tasklist]
### Meta Tasks
- [ ] Provide Week 1 Update Comment
- [ ] Provide Week 2 Update or Closeout Comment
```

While incomplete, I have started a task list of activity we should attempt to understand, emulate and test monitoring capabilities on.
```[tasklist]
### Rule Coverage Tasks
- [ ] First Occurrence of OAuth Application and Azure API Call
- [ ] Potential Password Spraying of O365/Entra ID Accounts
- [ ] First Occurrence of OAuth Application Calls to Exchange
- [ ] First Occurrence of User Leveraging Proxy Services for Azure
- [ ] App with application-only permissions accessing numerous emails (MSFT Recommended)
- [ ] Increase in app API calls to EWS after a credential update (MSFT Recommended)
- [ ] Increase in app API calls to EWS (MSFT Recommended)
- [ ] App metadata associated with suspicious mal-related activity (MSFT Recommended)
- [ ] Suspicious user created an OAuth app that accessed mailbox items (MSFT Recommended)
```

## Resources / References
* https://www.microsoft.com/en-us/security/blog/2024/01/25/midnight-blizzard-guidance-for-responders-on-nation-state-attack/

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.