Gootkit File Delivery
Description
This query surfaces alerts related to Gootkit and enriches with command and control information, which has been observed delivering ransomware.
Query · kql
AlertInfo | where Title =~ "Suspected delivery of Gootkit malware" // Below section is to surface active follow-on Command and Control as a result of the above behavior. Comment out the below joins to see // only file create events where the malware may be present but has not yet been executed. //// // Get alert evidence | join AlertEvidence on $left.AlertId == $right.AlertId // Look for C2 | join DeviceNetworkEvents on $left.DeviceId == $right.DeviceId | where InitiatingProcessFileName =~ "wscript.exe" and InitiatingProcessCommandLine has ".zip" and InitiatingProcessCommandLine has ".js" | summarize by RemoteUrl, RemoteIP , DeviceId, InitiatingProcessCommandLine, Timestamp, InitiatingProcessFileName, AlertId, Title, AccountName