Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

FeedsContatoPrivacidade© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
SOC335---CVE-2024-49138-Exploitation-Detected — Passo a passo de resposta a incidentes SOC335 para escalonamento de privilégios do CLFS CVE-2024-49138, abrangendo triagem de alertas, enriquecimento de threat intel, análise de árvore de processos e contenção. | Kitploit
Ferramentas/GitHubGitHub/fabianch20/soc335---cve-2024-49138-exploitation-detected
Gerenciamento de Indicadores de Comprometimento (IOC)Escalada de PrivilégiosAnálise de VulnerabilidadesAnálise de MalwareForensia DigitalInteligência de AmeaçasAprendizado e EducaçãoResposta a Incidentes

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Análise de Logs
Labs e Prática
GitHubfabianch20/soc335---cve-2024-49138-exploitation-detected

SOC335---CVE-2024-49138-Exploitation-Detected

Passo a passo de resposta a incidentes SOC335 para escalonamento de privilégios do CLFS CVE-2024-49138, abrangendo triagem de alertas, enriquecimento de threat intel, análise de árvore de processos e contenção.

Ver Repositório
há 16 diasAinda não revisado
Compartilhar

Rule CVE CVSS Status Verdict Host


> whoami

root@soc:~# cat case_file.txt

  Platform      : LetsDefend
  Case          : SOC335 - CVE-2024-49138 Exploitation Detected
  EventID       : 313
  Alert Time    : 2025-01-22T02:37:00+03:00
  Alert Type    : Privilege Escalation
  Difficulty    : Medium
  Role          : Security Analyst

  Hostname      : Victor
  IP Address    : 172.16.17.207
  Process User  : EC2AMAZ-ILGVOIN\LetsDefend
  Process Name  : svohost.exe   (masquerading svchost.exe)
  Process Path  : C:\temp\service_installer\svohost.exe
  Parent Proc   : C:\Windows\System32\WINDOWSPOWERSHELL\V1.0\powershell.exe
  File Hash     : b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9
  Device Action : Allowed

  MITRE ATT&CK  : T1059.001  PowerShell
                  T1055      Process Injection
                  T1068      Exploitation for Privilege Escalation
                  T1548      Abuse Elevation Control Mechanism
                  T1110      Brute Force

> ./playbook.sh --pivot-methodology

Metodologia de 5 fases, cada uma resolvida em WHO / WHAT / WHEN / WHY antes de pivotar para a seguinte.

┌─[ STEP 1: ALERT TRIAGE ]─────────────────────────────────────────────────────┐
│                                                                              │
│  WHO   : SIEM queue / SOC335 rule (EventID 313)                              │
│  WHAT  : svohost.exe spawned by powershell.exe outside System32              │
│  WHEN  : 2025-01-22 02:37:00 +03:00                                          │
│  WHY   : separates real EoP attempt from benign svc install                  │
│                                                                              │
│  $ filter process_name="svohost.exe" AND path!="*\System32\*"                │
│                                                                              │
│  PIVOT : hash + host isolated -> enrich with threat intel                    │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 2: THREAT INTEL ENRICHMENT ]──────────────────────────────────────────┐
│                                                                              │
│  WHO   : VirusTotal, CISA KEV, SentinelOne CVE DB                            │
│  WHAT  : hash flagged malicious; behavior maps to CVE-2024-49138 (CLFS EoP)  │
│  WHEN  : patched Dec-2024 Patch Tuesday; exploited pre-patch as 0-day, KEV-  │
│          listed                                                              │
│  WHY   : turns an unknown binary into a named, weaponized CVE with known TTPs│
│                                                                              │
│  $ vt hash b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9  │
│                                                                              │
│  PIVOT : malware + CVE confirmed -> validate on endpoint process tree        │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 3: ENDPOINT PROCESS TREE ]────────────────────────────────────────────┐
│                                                                              │
│  WHO   : Endpoint Security / EDR telemetry on host Victor                    │
│  WHAT  : child proc whoami.exe executes as NT AUTHORITY\SYSTEM               │
│  WHEN  : immediately after svohost.exe execution, same alert window          │
│  WHY   : proves exploitation SUCCEEDED, not merely attempted                 │
│                                                                              │
│  $ proctree --host Victor --pid 7640                                         │
│                                                                              │
│  PIVOT : escalation confirmed -> pivot to network logs for entry vector      │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 4: NETWORK & LOG PIVOT ]──────────────────────────────────────────────┐
│                                                                              │
│  WHO   : Log Management: RDP auth logs + firewall/netflow                    │
│  WHAT  : RDP brute force from 185.107.56.141; outbound traffic to C2         │
│  WHEN  : brute force precedes 02:37 alert; C2 traffic follows escalation     │
│  WHY   : completes the chain from initial access to impact; feeds IOC list   │
│                                                                              │
│  $ filter dst_ip=172.16.17.207 AND event_type=logon_failed,logon_success     │
│                                                                              │
│  PIVOT : full attack chain reconstructed -> containment & closure            │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 5: CONTAINMENT & CLOSURE ]────────────────────────────────────────────┐
│                                                                              │
│  WHO   : Incident responder / case owner                                     │
│  WHAT  : Device Action=Allowed -> malware NOT quarantined; host isolated     │
│  WHEN  : at alert time, within response SLA                                  │
│  WHY   : halts lateral movement/C2; documents evidence for TP closure        │
│                                                                              │
│  $ isolate-host Victor --reason "CVE-2024-49138 confirmed exploitation"      │
│                                                                              │
│  PIVOT : case closed as True Positive -> remediation (patch CLFS, harden RDP)│
└──────────────────────────────────────────────────────────────────────────────┘

> ./run_investigation.sh

[ Step 1 ] Alert Triage — SIEM / SOC335
$ cat alert_313.log

[i] EventID 313 | Rule: SOC335 - CVE-2024-49138 Exploitation Detected
[i] Parent -> powershell.exe (v1.0)
[i] Child  -> svohost.exe  "C:\temp\service_installer\svohost.exe"
[!] Legit svchost.exe NEVER runs outside C:\Windows\System32\
[+] ANSWER: filename masquerading detected (svohost vs svchost) -> escalate to full case

🔗 [LetsDefend SOC335 case data]

[ Step 2 ] Threat Intel Enrichment — VirusTotal + CVE research
$ vt hash b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9
Baixar ferramenta