
Walkthrough di incident response SOC335 per l'escalation di privilegi CLFS CVE-2024-49138, che copre il triage degli alert, l'arricchimento delle threat intel, l'analisi dell'albero dei processi e il containment.
> whoamiroot@soc:~# cat case_file.txt
Platform : LetsDefend
Case : SOC335 - CVE-2024-49138 Exploitation Detected
EventID : 313
Alert Time : 2025-01-22T02:37:00+03:00
Alert Type : Privilege Escalation
Difficulty : Medium
Role : Security Analyst
Hostname : Victor
IP Address : 172.16.17.207
Process User : EC2AMAZ-ILGVOIN\LetsDefend
Process Name : svohost.exe (masquerading svchost.exe)
Process Path : C:\temp\service_installer\svohost.exe
Parent Proc : C:\Windows\System32\WINDOWSPOWERSHELL\V1.0\powershell.exe
File Hash : b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9
Device Action : Allowed
MITRE ATT&CK : T1059.001 PowerShell
T1055 Process Injection
T1068 Exploitation for Privilege Escalation
T1548 Abuse Elevation Control Mechanism
T1110 Brute Force
> ./playbook.sh --pivot-methodologyMetodologia in 5 fasi, ciascuna risolta in WHO / WHAT / WHEN / WHY prima di passare alla successiva.
┌─[ STEP 1: ALERT TRIAGE ]─────────────────────────────────────────────────────┐
│ │
│ WHO : SIEM queue / SOC335 rule (EventID 313) │
│ WHAT : svohost.exe spawned by powershell.exe outside System32 │
│ WHEN : 2025-01-22 02:37:00 +03:00 │
│ WHY : separates real EoP attempt from benign svc install │
│ │
│ $ filter process_name="svohost.exe" AND path!="*\System32\*" │
│ │
│ PIVOT : hash + host isolated -> enrich with threat intel │
└──────────────────────────────────────────────────────────────────────────────┘
┌─[ STEP 2: THREAT INTEL ENRICHMENT ]──────────────────────────────────────────┐
│ │
│ WHO : VirusTotal, CISA KEV, SentinelOne CVE DB │
│ WHAT : hash flagged malicious; behavior maps to CVE-2024-49138 (CLFS EoP) │
│ WHEN : patched Dec-2024 Patch Tuesday; exploited pre-patch as 0-day, KEV- │
│ listed │
│ WHY : turns an unknown binary into a named, weaponized CVE with known TTPs│
│ │
│ $ vt hash b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9 │
│ │
│ PIVOT : malware + CVE confirmed -> validate on endpoint process tree │
└──────────────────────────────────────────────────────────────────────────────┘
┌─[ STEP 3: ENDPOINT PROCESS TREE ]────────────────────────────────────────────┐
│ │
│ WHO : Endpoint Security / EDR telemetry on host Victor │
│ WHAT : child proc whoami.exe executes as NT AUTHORITY\SYSTEM │
│ WHEN : immediately after svohost.exe execution, same alert window │
│ WHY : proves exploitation SUCCEEDED, not merely attempted │
│ │
│ $ proctree --host Victor --pid 7640 │
│ │
│ PIVOT : escalation confirmed -> pivot to network logs for entry vector │
└──────────────────────────────────────────────────────────────────────────────┘
┌─[ STEP 4: NETWORK & LOG PIVOT ]──────────────────────────────────────────────┐
│ │
│ WHO : Log Management: RDP auth logs + firewall/netflow │
│ WHAT : RDP brute force from 185.107.56.141; outbound traffic to C2 │
│ WHEN : brute force precedes 02:37 alert; C2 traffic follows escalation │
│ WHY : completes the chain from initial access to impact; feeds IOC list │
│ │
│ $ filter dst_ip=172.16.17.207 AND event_type=logon_failed,logon_success │
│ │
│ PIVOT : full attack chain reconstructed -> containment & closure │
└──────────────────────────────────────────────────────────────────────────────┘
┌─[ STEP 5: CONTAINMENT & CLOSURE ]────────────────────────────────────────────┐
│ │
│ WHO : Incident responder / case owner │
│ WHAT : Device Action=Allowed -> malware NOT quarantined; host isolated │
│ WHEN : at alert time, within response SLA │
│ WHY : halts lateral movement/C2; documents evidence for TP closure │
│ │
│ $ isolate-host Victor --reason "CVE-2024-49138 confirmed exploitation" │
│ │
│ PIVOT : case closed as True Positive -> remediation (patch CLFS, harden RDP)│
└──────────────────────────────────────────────────────────────────────────────┘
> ./run_investigation.sh$ cat alert_313.log
[i] EventID 313 | Rule: SOC335 - CVE-2024-49138 Exploitation Detected
[i] Parent -> powershell.exe (v1.0)
[i] Child -> svohost.exe "C:\temp\service_installer\svohost.exe"
[!] Legit svchost.exe NEVER runs outside C:\Windows\System32\
[+] ANSWER: filename masquerading detected (svohost vs svchost) -> escalate to full case
🔗 [LetsDefend SOC335 case data]
$ vt hash b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9