chainsaw icon indicating copy to clipboard operation
chainsaw copied to clipboard

Microsoft Defender / Antivirus detections removed in new releases

Open AnthoLaMalice opened this issue 1 year ago • 7 comments

Hey guys,

I have observed that the latest version of Chainsaw no longer seems to report Microsoft Defender/AV detection.

I ran both v2.9.0 and v2.8.0 on the same log set, which I know contains Microsoft Defender detection for CVE-2021-31207. The default raw output was redirected to a file for testing.

v2.9.0 vs v2.8.0 :

image

As you can see v2.8.0 indeed showed Microsoft Defender detection which is not the case for v2.9.0.

It also seems that with version 2.8.0, if you output your results to a csv or json file, a specific file has been created for AV detection, which is not the case with version 2.9.0.

Is there an explanation for this?

Thanks for your work!

AnthoLaMalice avatar May 22 '24 13:05 AnthoLaMalice

Hey @AnthoLaMalice

Thanks for flagging this. I'll take a look next week and get back to you after I've figured out what's going on.

FranticTyping avatar May 22 '24 17:05 FranticTyping

Does undoing this https://github.com/WithSecureLabs/chainsaw/commit/9e04039d571e64d8ef828be284bae2f2127a2860 change to the Chainsaw windows_defender.yml rule fix the behaviour?

alexkornitzer avatar May 23 '24 16:05 alexkornitzer

It indeed seems like it fixed the issue : image

AnthoLaMalice avatar May 23 '24 17:05 AnthoLaMalice

Awesome, okay that should not break it but now we know where to look.

alexkornitzer avatar May 23 '24 17:05 alexkornitzer

I tried to reproduce this using the same rules but only switching the Chainsaw version on Windows between v2.8.1 and v2.9.0 but I was unable to. They produced identical results apart from a few lines changing positions on the csv which is expected. 1116 and 1117 events appeared correctly using EVTX Attack Samples to test.

I noticed in the screenshots you were using Linux so this may be a platform specific bug?

reece394 avatar May 27 '24 12:05 reece394

@AnthoLaMalice are you able to provide the event log so that I can try and replicate this behaviour?

@reece394 thank you for doing some further triage.

alexkornitzer avatar May 27 '24 12:05 alexkornitzer

Yep, not able to replicate on my machine using the example EVTX files. Screenshot 2024-05-27 at 14 21 48

alexkornitzer avatar May 27 '24 13:05 alexkornitzer