Diagram with a bee in the center surrounded by blue and red arrows. Blue arrows lead to icons of documents and alerts, while red arrows lead to security symbols. The word upwind is in the top left corner.

Detect Malicious File Activities 

Denise Ashur May 25, 2024

We are excited to announce a significant new capability in the Upwind Cloud Security Platform – threat detections for malicious file-based activity.

Upwind’s threat detection and response capabilities have always allowed customers to detect and respond to threats in real time, powered by our innovative eBPF-based sensor. With this new capability, Upwind’s threat detection capabilities will give you even deeper protection, analyzing suspicious and malicious file-based activities.

How Does Upwind Detect File-Based Activities?

Upwind will now detect suspicious and malicious “file activities,” including read, write & truncate (delete). We do this through the Upwind eBPF sensor, which monitors file access and collects raw data on every process activity involving files.

Screenshot-2024-05-20-at-11.29.50%E2%80%AFAM-1024x488

Upwind’s eBPF sensor not only monitors file activities, it also enriches that data with information that better explains an event’s context, and provides insights into the actions taken on the file, including read, write, and truncate (delete). 

Additionally, the Upwind sensor also provides comprehensive metadata relating to the file itself, including details such as the owner, time and date of creation, permissions, size, and MD5 hash. This event context, behavior analysis, and comprehensive metadata is then paired with extensive insights into the processes responsible for these actions, providing a deeper understanding of the context surrounding file activities.

Benefits of Detecting File-Based Activities

Detecting behavior and suspicious actions performed on files is crucial for all organizations in order to safeguard against a wide range of threats and patterns indicative of malicious activity, such as unauthorized access to sensitive files and evidence tampering. By utilizing this information, customers can rapidly identify file-based threats, recognize patterns of malicious activity within their environment and take proactive measures against file-based risks.

Screenshot-2024-05-20-at-11.30.23%E2%80%AFAM-1024x346

Upwind’s file-based detections give you the ability to:

  • Monitor All File Activities: view and detect suspicious and malicious file activities performed by processes. 
  • Detect Common File-Based MITRE Tactics: Easily identify common MITRE tactics in files, such as:
    • Sensitive File Access: an attacker leverages a binary without user-prompt commands to access sensitive system files such as /etc/passwd. This type of unauthorized access could potentially compromise system integrity and lead to security breaches. 
    • Reconnaissance File Access: an attacker leverages a binary to access and read files that contain sensitive information such as user accounts, group memberships, network configurations and system logs.
    • Defense Evasion: an attacker leverages a resource in your environment to modify command history log files. This type of activity indicates potential attempts to conceal traces by manipulating command execution records, which may suggest unauthorized or malicious actions within your environment.
    • Direct Access To Filesystem: an attacker leverages a resource in your environment to access a file using direct access to the file system. These files represent physical storage devices like hard drives, SSDs, and external drives. Unauthorized access to these devices could indicate attempts to install malware, steal data, manipulate partitions, or perform unauthorized actions.
  • Prioritize File-Based Risks & Threats: All file-based threat detections will surface as Issues within the Upwind Platform, rapidly identifying potential risks and threats.
  • View Comprehensive File Information: For each file event/detection, view file information including the file owner, date and time of file creation, file permissions and file size.

Use this capability to easily monitor and identify suspicious and malicious file-based activities, respond to file-based threats in real time, and proactively safeguard against file-based threats.

Learn More

To learn more about Upwind’s file-based threat detections, visit the Upwind Documentation Center (Login Required), or schedule a demo.

Contents

Further Reading

5 Back to School Security Predictions: The Attacker Class Average Just Moved
5 Back to School Security Predictions: The Attacker Class Average Just Moved

5 Back to School Security Predictions: The Attacker Class Average Just Moved

Back to school season is here, which makes this a good moment to look at what changed in the threat landscape over the summer. AI-assisted attackers haven't climbed toward the top of the field so much as filled in the middle of it and the middle is the population almost no security program was designed…
org chart - dark mode

The Org Chart is The Wrong Security Boundary

The department model of dividing companies into groups earned its place. Finance gets the finance applications, engineering gets the repositories, HR gets the HRIS, and the boundaries hold because software was bought per function and used per function. Identity and access management platforms, such as Active Directory and Okta, were built around exactly that. Groups…
behind-the-curtain-part-03

What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part III

Recap In Part I and Part II, we: Networking and VPC Mode Network Isolation Testing The microVM is assigned an IPv6 address matching the value in the JWT. Across multiple runs, all addresses shared the same 2600:1f18::/32 prefix, but cross-microVM communication always failed. We attempted to reach the host EC2 IMDS by manipulating the route…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS