26
Ransomware vs. SysAdmin ERIK LOEF

SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

Embed Size (px)

Citation preview

Page 1: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

Ransomware vs. SysAdminERIK LOEF

Page 2: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

B

Page 3: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

Erik Loef@erikloef

CTO

Page 4: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin
Page 5: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

2day• Ransomware general• DEMO

• Application Whitelisting• DEMO

• Fileserver Protection• DEMO

• Windows 10 Fall Creators Update• DEMO

• Recap

Page 6: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin
Page 7: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

general

variants• Lockers• CryptersKnown variants• Aids virus (1989)• Police | Fake Anitvirus• Cryptolocker/TelsaCrypt/Wildfirelocker

Page 8: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

DEMORansomware end user experience

Page 9: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

the other side

Page 10: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

Pay

Page 11: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin
Page 12: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

Application Whitelisting

let‘s take a look at SRP

Page 13: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

Application Whitelisting

Microsoft Options

• AppLocker/Device Guard

• Good – Old – SRP

Third Party solutions

• RES

• Lumension

• Symantec

• and many many others

Page 14: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

SRP

Advantages

• Working since Windows XP / Server 2003

• You can put it in ‘monitoring mode’ as a start

• Easy, everybody can do this

• Free

• Many examples and tools, I advise take a look at CryptoPrevent

Page 15: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

DEMORansomware & SRP

Page 16: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

File Server Resource Manager

• Quota Management

• File Screening Management

• Storage Reports Management

• Classification Management

Page 17: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

File Screening Management

• unauthenticated API

• active vs. passive

• command execution

SEE https://fsrm.experiant.ca/

Page 18: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

DEMORansomware & FSRM

Page 19: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin
Page 20: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin
Page 21: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin
Page 22: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin
Page 23: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

DEMOControlled Folder AccessAttack Surface Reduction Rules

Page 24: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

RECAP

• Ransomware still has the attention!

• You can fix this! (without high investments)

• Windows 10 Fall Creators Update first OS with specific built-in anti- Ransomwaremechanismes

Page 25: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

LINKS• https://technet.microsoft.com/en-us/library/cc732431(v=ws.11).aspx

• https://fsrm.experiant.ca/

• http://windowsitpro.com/systems-management/q-how-can-we-verify-software-restriction-policy-srp-rule-we-defined-one-our-appli

• https://technet.microsoft.com/en-us/library/bb457006.aspx

• https://www.foolishit.com/cryptoprevent-malware-prevention/

• https://technet.microsoft.com/en-us/library/3f1faff2-cf65-42ce-9df8-a22bac671047

• https://www.nomoreransom.org/

• https://www.fraudehelpdesk.nl/

• www.twitter.com/erikloef

• https://gallery.technet.microsoft.com/scriptcenter/Protect-your-File-Server-f3722fce

• http://blog.netwrix.com/2016/04/11/ransomware-protection-using-fsrm-and-powershell/

Page 26: SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin

Thanks to our event sponsors

Silver

Gold