
Windows RPC firewall that audits, detects, and blocks malicious remote procedure calls to prevent lateral movement, reconnaissance, and exploitation of RPC-based attacks like DCSync and ZeroLogon.
Check out our RPC Firewall blog post or our BlackHat talk to gain better understanding of RPC, RPC attacks, and the solution: RPC Firewall.
Join our |Zero| Labs Slack Community workspace for any questions, issues, or simply to shout out.
We would love to hear from you also via email (if you are that type of person). Contact us at [email protected]
The following tutorial shows basic installation and setup of RPC Firewall, as well as a demo of how it protects against various RPC-based attacks.
RPC is the underlying mechanism which is used for numerous lateral movement techniques, reconnaissance, relay attacks, or simply to exploit vulnerable RPC services.
DCSync attack? over RPC. Remote DCOM? over RPC. WMIC? over RPC. SharpHound? over RPC. PetitPotam? over RPC. PsExec? over RPC. ZeroLogon? over RPC... well, you get the idea :)
Throughout this document, we will use the following terms:
Can be used to to audit all remote RPC calls. Once executing any remote attack tools, you will see which RPC UUIDs and Opnums were called remotely.
See an example configuration here.
When the RPCFW Configuration is configured to audit, events are written to the Windows Event Log. RPC Filter events are written to the security log, with event ID 5712. RPC Firewall logs are written at Application/RPCFW.
Users can forward these logs to their SIEM, and use it to create baselines of remote RPC traffic for various servers. Once an abnormal RPC call is audited, use it to trigger an alert for your SOC team.
We integrated several Sigma rules which can be used to detect unusual RPC activities and attacks.
The RPCFW Configuration can be configured to block & audit only potentially malicious RPC calls. All other RPC calls are not audited to reduce noise and improve performance.
Once a potentially malicious RPC call is detected, it is blocked and audited. This could be used to alert your SOC team, while keeping your servers protected.
To supplement protection, you can use the RPC Filtering capabilities, which are also supported via the RpcFwManager.exe.
An example of such configuration can be found here.
It is made up from 3 components:
While there are pros and cons for using each method, there are a couple of major benefits for using RPC Firewall which require special attention. These are:
On the other hand, RPC Filters are greate for bulk allow or deny of entire UUIDs, as they do so without any issues.
Prior to running any command, it is recommended to check the status of the deployment. This is done by issuing the '/status' command:
RpcFwManager.exe /status
This will show the status of both the RPC Firewall and the RPC Filters. This will output detailed information about the installation status, and also the running status of the deployment.
Almost every command can be suffixed with fw or flt at the end. This tells RPCFW Manager whether the command is applied to RPC Firewall ('fw'), RPC Filters ('flt') or both when not using any suffix.
Peform installation of the relevant feature (RPC Filters / RPC FIrewall / both).
Make sure the event viewer is closed during install/uninstall. Also, it is good practice to stop & uninstall before installation, to make sure there aren't any previous versions installed.
RpcFwManager.exe /stop
RpcFwManager.exe /uninstall
RpcFwManager.exe /install
Uninstalling does the opposite. Also here it is good practice to ensure the service is stopped prior to uninstallation.
RpcFwManager.exe /stop
RpcFwManager.exe /uninstall
RPC Filters, by their nature, are applied system-wide, to any RPC server. Applying such filters is also persistent across reboots. Any new or old process will be protected by RPC Filters, according to the RPCFW Configuration.
RPC Firewall is injected and protects any RPC server process which is listening for remote RPC calls. This is done by injecting RPC Firewall into processes which load the RPCRT4.DLL (the RPC Runtime). Once loaded, RPC Firewall will detect whether the RPC server is listening for remote RPC calls. If not, it unloads itself. If the process is a valid RPC server, the rpcFirewall starts to audit & monitor incoming RPC calls, according to the RPCFW Configuration.
The recommended method to protect RPC services is by using the '/start' command. This starts the RPC Firewall service (for 'fw' or no suffix), and creates RPC Filters (for 'flt' or no suffix).
RpcFwManager.exe /start