SentinelOne recently launched Singularity Operations Center, the new unified console, to centralize workflows and accelerate detection, triage, and investigation for an efficient and seamless analyst experience. This pivotal update includes integrated navigation to improve workflows and new and enhanced capabilities such as unified alerts management. Providing a deeper look into the Operations Center, this blog post focuses on how unified alert management enables faster and more comprehensive investigations for todays security teams.
Traditionally, security analysts must deploy multiple security tools to protect their organizations. Each individual tool manages alerts differently in addition to disconnected workflows among the tools themselves. With this approach, analysts are unable to correlate alerts across disparate solutions. This fragmented approach complicates the triage process, leading to an increased mean time to respond (MTTR) and potential oversight during an investigation.
To combat these challenges, SentinelOne developed the unified console to provide broader visibility and management across the security ecosystem. The Operations Center empowers teams to consolidate and centralize all security alerts into a single cohesive queue, including those from SentinelOne native solutions and industry-leading partners. This approach eliminates the need to pivot among disconnected consoles and work within disjointed workflows, providing seamless SOC workflows and facilitating rapid response to threats.
Engineered for speed and efficiency, LockBit is an advanced and pervasive ransomware strain. It leverages sophisticated encryption algorithms to rapidly lock down critical data within targeted networks. LockBit employs double extortion techniques, where attackers exfiltrate sensitive data before encryption and threaten to publish it on dedicated leak sites if their demands are unmet. It operates under a Ransomware-as-a-Service (RaaS) model, enabling affiliates to deploy the malware in exchange for a portion of ransom proceeds. Its attack vectors often include exploitation of vulnerabilities, phishing, and lateral movement within compromised networks, making it a versatile and potent threat. Continuous updates and modular capabilities allow LockBit to bypass traditional security measures, emphasizing the need for advanced detection and response strategies in defending against this threat.
Lets explore how to investigate a LockBit infection in the Singularity Operations Center. After logging into the console, the Overview Dashboard provides a broad view of security alerts and related assets. There are multiple open alerts, ten of which are of high or critical severity. From the numerous open alerts, this example will focus on the critical alerts.
The drill-down creates a filter that allows analysts to quickly view new alerts with critical and high severity. To start the triage, these alerts will be assigned to an analyst. The Alert Status will be updated to In Progress.
Next, the alerts are grouped by File Hash and Asset Name to see the targeted assets and the extent of the infection. This is done by clicking on the + Add Column button at the top of the page, where filters are available. Analysts can group by the available columns on the page to organize the information.
Once the alerts are grouped, it is clear that the critical alerts are related to one hash, and the lower severity alerts are related to svchost.exe. Lets focus on the hash with critical alerts. The hash is detected on four different assets, indicating that the attacker or malware can laterally move through the network. The file name changes on subsequently infected devices.
Lets investigate the first occurrence of that hash on TheBorg machine in the Ransomware artifacts detected alert. The Alerts Details view provides more information about the threat. These details indicate that a Jeanluc user in the STARFLEET domain executed the process, which originated from explorer.exe, indicating that the user opened the file from the file system.
The Indicators tab provides more granular details, such as behavioral indicators. The severity icons specify that the most severe events are related to ransomware behavior, such as shadow copy deletion and file encryption. These behavioral indicators tell us a story of the malwares behavior.
To validate the files maliciousness and gain confidence in mitigating the threat as a true positive, analysts can search for the files hash in the threat intelligence sources such as the Singularity Threat Intelligence solution or VirusTotal integration. In this instance, it is clear that Singularity Threat Intelligence attributes it to LOCKBIT.V2. Clicking through shows more known details about the threat powered by Mandiant. We can see that Mandiant is already tracking it as LockBit Red associated with UNC2758.
Lets explore the Process Graph to visually inspect what happened. Here, the ResistanceIsFutile.exe process is running PowerShell and CMD commands. The PowerShell process in the Command Line attribute looks for all domain computers to prepare for lateral movement, adding a random delay between requests. Clicking through shows many of the actions indicated before as well as all the IP Connect events communicating with other assets.
The new Graph Explorer also illustrates the connections between alerts and assets. Lets filter for all Assets with high or critical severity alerts. In this example, all assets have two critical alerts: Ransomware artifacts and the renamed malware 9672B0.exe. This confirms the correlation between the original alert and other alerts on all the servers and endpoints in the graph.
This information confidently confirms that a ransomware infection is replicating in the network. Analysts can now mitigate all the alerts before proceeding with further investigation. All actions we performed are visible in the History tab of the alert details, lessening the need for extensive notes of the investigation process.
The next step is to hunt for indicators of compromise in Event Search and include them in the incident report. Drill down to Event Search from the Alert Details drawer and see all the events related to the alerts Storyline. View different tabs for more specific event categories, such as DNS, Network Actions, or Scheduled Tasks.
Analysts can also write hunting PowerQueries to get more details and group events together. The following example lists all commands executed by the LockBit processes for each endpoint. This information can be used to write more hunting queries, see if similar behavior has been detected in the past, or write new detections for this behavior.
dataSource.name='SentinelOne' event.type='Process Creation' src.process.parent.name in ('ResistanceIsFutile.exe', '9672B0.exe')| let cmdline = format("%s %s", tgt.process.name, tgt.process.cmdline)| group count(), cmdlines=array_agg_distinct(cmdline) by endpoint.name, src.process.name
The following PowerQuery can be used to see the list of ports on which the initially compromised host communicated.
endpoint.name = 'TheBorg-KY3H' event.type='IP Connect' event.network.direction = 'OUTGOING' | group count=count(), dst.ports=array_agg_distinct(dst.port.number) by dst.ip.address| sort - dst.ports
There are many other queries that can be leveraged to look for anomalies in the data. The most critical part of this process is carefully examining our events and distilling the malwares unique behavior. The Search Library provides hunting queries to help kickstart this process.
The Singularity Operations Center is Generally Available (GA) to all cloud-native customers. We invite you to explore the new console and experience how our innovative approach enhances and unifies security operations. Our Singularity Platform is designed to meet the evolving needs of modern SOCs, providing the flexibility and scalability required to handle the growing complexity of todays threat landscape.
Not a customer, but want to learn more? Meet our team for a demo to see how you can get started with the Singularity Platform, or visit our self-guided product tours.
Singularity Platform
Singularity enables unfettered visibility, industry-leading detection, and autonomous response. Discover the power of AI-powered, enterprise-wide cybersecurity.
Read the original here:
Singularity Operations Center | Unified Security Operations for Rapid Triage - SentinelOne
- Decoding the SS25 trends on PV New York's next show - Premiere Vision [Last Updated On: November 26th, 2023] [Originally Added On: November 26th, 2023]
- Jason Isaacs talks playing desperately troubled and unhappy, haunted Cary Grant in ITVX biopic - Yahoo News UK [Last Updated On: November 26th, 2023] [Originally Added On: November 26th, 2023]
- What I fear about generative AI, By Uddin Ifeanyi - Premium Times [Last Updated On: November 26th, 2023] [Originally Added On: November 26th, 2023]
- Palia Welcomes A New Quest-Giver NPC, Flow Trea Groves, And A ... - MMOs.com [Last Updated On: November 26th, 2023] [Originally Added On: November 26th, 2023]
- Mneskin: how Honey (Are u coming) became a live anthem - WECB [Last Updated On: November 26th, 2023] [Originally Added On: November 26th, 2023]
- The Slate Speaks: Childhood media shaping us today - The Slate Online [Last Updated On: November 26th, 2023] [Originally Added On: November 26th, 2023]
- AI Revolution The Change. The creation of computer systems that ... - Medium [Last Updated On: November 26th, 2023] [Originally Added On: November 26th, 2023]
- HUMANITY IN AN AUTOMATED WORLD - THE SINGULARITY ... - The HR Director Magazine [Last Updated On: November 26th, 2023] [Originally Added On: November 26th, 2023]
- If AI Takes Over, What Will You Do? - Medium [Last Updated On: November 26th, 2023] [Originally Added On: November 26th, 2023]
- Sam Altman is back in the driver's seat at OpenAI next stop ... - TechRadar [Last Updated On: November 26th, 2023] [Originally Added On: November 26th, 2023]
- Scientists 3D Print a Complex Robotic Hand With Bones, Tendons, and Ligaments - Singularity Hub [Last Updated On: November 26th, 2023] [Originally Added On: November 26th, 2023]
- OpenAI Mayhem: What We Know Now, Don't Know Yet, and What Could Be Next - Singularity Hub [Last Updated On: November 26th, 2023] [Originally Added On: November 26th, 2023]
- The Singularity Is Fear - by Tomas Pueyo - Uncharted Territories [Last Updated On: November 26th, 2023] [Originally Added On: November 26th, 2023]
- This Week's Awesome Tech Stories From Around the Web (Through February 3) - Singularity Hub [Last Updated On: February 4th, 2024] [Originally Added On: February 4th, 2024]
- This Week's Awesome Tech Stories From Around the Web (Through March 16) - Singularity Hub [Last Updated On: March 23rd, 2024] [Originally Added On: March 23rd, 2024]
- Frax Finance Aims for $100B Locked Value with Roadmap - Crypto Times [Last Updated On: March 23rd, 2024] [Originally Added On: March 23rd, 2024]
- Critical Survey: Singularity Future Technology (NASDAQ:SGLY) and DSV A/S (OTCMKTS:DSDVF) - Defense World [Last Updated On: March 23rd, 2024] [Originally Added On: March 23rd, 2024]
- The Father Of The Singularity Dead At 79 | GIANT FREAKIN ROBOT - Giant Freakin Robot [Last Updated On: March 23rd, 2024] [Originally Added On: March 23rd, 2024]
- Vernor Vinge, father of the tech singularity, has died at age 79 - Ars Technica [Last Updated On: March 23rd, 2024] [Originally Added On: March 23rd, 2024]
- Vernor Vinge, influential sci-fi author who warned of AI 'Singularity,' has died - Popular Science [Last Updated On: March 23rd, 2024] [Originally Added On: March 23rd, 2024]
- Vernor Vinge, Author Who Popularized AI Singularity, Dies at 79 - TheWrap [Last Updated On: March 23rd, 2024] [Originally Added On: March 23rd, 2024]
- Singularity Growth Invests Rs 400 Cr in Akshayakalpa, Lohum, and Others - Startup Story [Last Updated On: April 20th, 2024] [Originally Added On: April 20th, 2024]
- Cannes' Directors' Fortnight sets its sights on singularity - Cineuropa [Last Updated On: April 20th, 2024] [Originally Added On: April 20th, 2024]
- Exploding Stars Are Rarebut if One Was Close Enough, It Could Threaten Life on Earth - Singularity Hub [Last Updated On: April 20th, 2024] [Originally Added On: April 20th, 2024]
- Scientists Create Atomically Thin Gold With Century-Old Japanese Knife Making Technique - Singularity Hub [Last Updated On: April 20th, 2024] [Originally Added On: April 20th, 2024]
- Boston Dynamics Says Farewell to Its Humanoid Atlas RobotThen Brings It Back Fully Electric - Singularity Hub [Last Updated On: April 20th, 2024] [Originally Added On: April 20th, 2024]
- Revolutionary Soundscape: "Journey into Singularity" by Westfalen Winds - elblog.pl [Last Updated On: April 20th, 2024] [Originally Added On: April 20th, 2024]
- Ray Kurzwell revisits AI singularity prediction 20 years on | Technology | sfexaminer.com - San Francisco Examiner [Last Updated On: April 20th, 2024] [Originally Added On: April 20th, 2024]
- Cell Therapies Now Beat Back Once Untreatable Blood Cancers. Scientists Are Making Them Even Deadlier. - Singularity Hub [Last Updated On: April 20th, 2024] [Originally Added On: April 20th, 2024]
- Black hole singularities defy physics. New research could finally do away with them. - Space.com [Last Updated On: June 2nd, 2024] [Originally Added On: June 2nd, 2024]
- Scientists Smashed a Spacecraft Into an Asteroid. Here's What They're Learning From the Aftermath. - Singularity Hub [Last Updated On: June 10th, 2024] [Originally Added On: June 10th, 2024]
- This Week's Awesome Tech Stories From Around the Web (Through June 8) - Singularity Hub [Last Updated On: June 10th, 2024] [Originally Added On: June 10th, 2024]
- The First Soil Sample From the Far Side of the Moon Is Headed Home on China's Chang'e-6 - Singularity Hub [Last Updated On: June 10th, 2024] [Originally Added On: June 10th, 2024]
- Why We Can't Avoid Singularity Inside Every Black Hole - Worldatlas.com [Last Updated On: June 10th, 2024] [Originally Added On: June 10th, 2024]
- This Week's Awesome Tech Stories From Around the Web (Through June 15) - Singularity Hub [Last Updated On: June 21st, 2024] [Originally Added On: June 21st, 2024]
- SNL: Anthony Michael Hall on RDJ Bond, Sketches, "Singularity" Update - Bleeding Cool News [Last Updated On: June 21st, 2024] [Originally Added On: June 21st, 2024]
- The AI Singularity Is Nothing to Fear - hackernoon.com [Last Updated On: June 21st, 2024] [Originally Added On: June 21st, 2024]
- Sam Sammane Announces the Release of His New Book: "The Singularity of Hope: Humanity's Role in an AI ... - AccessWire [Last Updated On: June 21st, 2024] [Originally Added On: June 21st, 2024]
- The Singularity Heist: When AIs Crave Crypto | by Anthony Williams | Jun, 2024 - DataDrivenInvestor [Last Updated On: June 21st, 2024] [Originally Added On: June 21st, 2024]
- SentinelOne receives top accolades for Singularity Cloud Security - ChannelLife New Zealand [Last Updated On: July 14th, 2024] [Originally Added On: July 14th, 2024]
- Google's AI visionary says we'll 'expand intelligence a millionfold by 2045' thanks to nanobots, the tech will resurrect the dead, and we're all going... [Last Updated On: July 14th, 2024] [Originally Added On: July 14th, 2024]
- The Singularity Is Nearer: When We Merge with AI - Cool Hunting [Last Updated On: July 14th, 2024] [Originally Added On: July 14th, 2024]
- Transhumanist author predicts artificial super-intelligence, immortality, and the Singularity by 2045 - TechSpot [Last Updated On: July 14th, 2024] [Originally Added On: July 14th, 2024]
- Lord Bendtner acquires Team Singularity, makes other esports investments - Esports News UK [Last Updated On: July 22nd, 2024] [Originally Added On: July 22nd, 2024]
- Ray Kurzweil Still Lives in Utopia - Nautilus [Last Updated On: July 22nd, 2024] [Originally Added On: July 22nd, 2024]
- Unconventional Superconductivity: The Peculiar Case of Griffith Singularity - SciTechDaily [Last Updated On: July 22nd, 2024] [Originally Added On: July 22nd, 2024]
- OpenAIs Project Strawberry Said to Be Building AI That Reasons and Does Deep Research - Singularity Hub [Last Updated On: July 22nd, 2024] [Originally Added On: July 22nd, 2024]
- This Weeks Awesome Tech Stories From Around the Web (Through July 20) - Singularity Hub [Last Updated On: July 22nd, 2024] [Originally Added On: July 22nd, 2024]