SentinelOne recently launched Singularity Operations Center, the new unified console, to centralize workflows and accelerate detection, triage, and investigation for an efficient and seamless analyst experience. This pivotal update includes integrated navigation to improve workflows and new and enhanced capabilities such as unified alerts management. Providing a deeper look into the Operations Center, this blog post focuses on how unified alert management enables faster and more comprehensive investigations for todays security teams.
Traditionally, security analysts must deploy multiple security tools to protect their organizations. Each individual tool manages alerts differently in addition to disconnected workflows among the tools themselves. With this approach, analysts are unable to correlate alerts across disparate solutions. This fragmented approach complicates the triage process, leading to an increased mean time to respond (MTTR) and potential oversight during an investigation.
To combat these challenges, SentinelOne developed the unified console to provide broader visibility and management across the security ecosystem. The Operations Center empowers teams to consolidate and centralize all security alerts into a single cohesive queue, including those from SentinelOne native solutions and industry-leading partners. This approach eliminates the need to pivot among disconnected consoles and work within disjointed workflows, providing seamless SOC workflows and facilitating rapid response to threats.
Engineered for speed and efficiency, LockBit is an advanced and pervasive ransomware strain. It leverages sophisticated encryption algorithms to rapidly lock down critical data within targeted networks. LockBit employs double extortion techniques, where attackers exfiltrate sensitive data before encryption and threaten to publish it on dedicated leak sites if their demands are unmet. It operates under a Ransomware-as-a-Service (RaaS) model, enabling affiliates to deploy the malware in exchange for a portion of ransom proceeds. Its attack vectors often include exploitation of vulnerabilities, phishing, and lateral movement within compromised networks, making it a versatile and potent threat. Continuous updates and modular capabilities allow LockBit to bypass traditional security measures, emphasizing the need for advanced detection and response strategies in defending against this threat.
Lets explore how to investigate a LockBit infection in the Singularity Operations Center. After logging into the console, the Overview Dashboard provides a broad view of security alerts and related assets. There are multiple open alerts, ten of which are of high or critical severity. From the numerous open alerts, this example will focus on the critical alerts.
The drill-down creates a filter that allows analysts to quickly view new alerts with critical and high severity. To start the triage, these alerts will be assigned to an analyst. The Alert Status will be updated to In Progress.
Next, the alerts are grouped by File Hash and Asset Name to see the targeted assets and the extent of the infection. This is done by clicking on the + Add Column button at the top of the page, where filters are available. Analysts can group by the available columns on the page to organize the information.
Once the alerts are grouped, it is clear that the critical alerts are related to one hash, and the lower severity alerts are related to svchost.exe. Lets focus on the hash with critical alerts. The hash is detected on four different assets, indicating that the attacker or malware can laterally move through the network. The file name changes on subsequently infected devices.
Lets investigate the first occurrence of that hash on TheBorg machine in the Ransomware artifacts detected alert. The Alerts Details view provides more information about the threat. These details indicate that a Jeanluc user in the STARFLEET domain executed the process, which originated from explorer.exe, indicating that the user opened the file from the file system.
The Indicators tab provides more granular details, such as behavioral indicators. The severity icons specify that the most severe events are related to ransomware behavior, such as shadow copy deletion and file encryption. These behavioral indicators tell us a story of the malwares behavior.
To validate the files maliciousness and gain confidence in mitigating the threat as a true positive, analysts can search for the files hash in the threat intelligence sources such as the Singularity Threat Intelligence solution or VirusTotal integration. In this instance, it is clear that Singularity Threat Intelligence attributes it to LOCKBIT.V2. Clicking through shows more known details about the threat powered by Mandiant. We can see that Mandiant is already tracking it as LockBit Red associated with UNC2758.
Lets explore the Process Graph to visually inspect what happened. Here, the ResistanceIsFutile.exe process is running PowerShell and CMD commands. The PowerShell process in the Command Line attribute looks for all domain computers to prepare for lateral movement, adding a random delay between requests. Clicking through shows many of the actions indicated before as well as all the IP Connect events communicating with other assets.
The new Graph Explorer also illustrates the connections between alerts and assets. Lets filter for all Assets with high or critical severity alerts. In this example, all assets have two critical alerts: Ransomware artifacts and the renamed malware 9672B0.exe. This confirms the correlation between the original alert and other alerts on all the servers and endpoints in the graph.
This information confidently confirms that a ransomware infection is replicating in the network. Analysts can now mitigate all the alerts before proceeding with further investigation. All actions we performed are visible in the History tab of the alert details, lessening the need for extensive notes of the investigation process.
The next step is to hunt for indicators of compromise in Event Search and include them in the incident report. Drill down to Event Search from the Alert Details drawer and see all the events related to the alerts Storyline. View different tabs for more specific event categories, such as DNS, Network Actions, or Scheduled Tasks.
Analysts can also write hunting PowerQueries to get more details and group events together. The following example lists all commands executed by the LockBit processes for each endpoint. This information can be used to write more hunting queries, see if similar behavior has been detected in the past, or write new detections for this behavior.
dataSource.name='SentinelOne' event.type='Process Creation' src.process.parent.name in ('ResistanceIsFutile.exe', '9672B0.exe')| let cmdline = format("%s %s", tgt.process.name, tgt.process.cmdline)| group count(), cmdlines=array_agg_distinct(cmdline) by endpoint.name, src.process.name
The following PowerQuery can be used to see the list of ports on which the initially compromised host communicated.
endpoint.name = 'TheBorg-KY3H' event.type='IP Connect' event.network.direction = 'OUTGOING' | group count=count(), dst.ports=array_agg_distinct(dst.port.number) by dst.ip.address| sort - dst.ports
There are many other queries that can be leveraged to look for anomalies in the data. The most critical part of this process is carefully examining our events and distilling the malwares unique behavior. The Search Library provides hunting queries to help kickstart this process.
The Singularity Operations Center is Generally Available (GA) to all cloud-native customers. We invite you to explore the new console and experience how our innovative approach enhances and unifies security operations. Our Singularity Platform is designed to meet the evolving needs of modern SOCs, providing the flexibility and scalability required to handle the growing complexity of todays threat landscape.
Not a customer, but want to learn more? Meet our team for a demo to see how you can get started with the Singularity Platform, or visit our self-guided product tours.
Singularity Platform
Singularity enables unfettered visibility, industry-leading detection, and autonomous response. Discover the power of AI-powered, enterprise-wide cybersecurity.
More here:
Singularity Operations Center | Unified Security Operations for Rapid Triage - SentinelOne
- Downloads - Singularity Viewer [Last Updated On: December 25th, 2016] [Originally Added On: December 25th, 2016]
- What is Singularity (the)? - Definition from WhatIs.com [Last Updated On: January 5th, 2017] [Originally Added On: January 5th, 2017]
- When Electronic Witnesses Are Everywhere, No Secret's Safe - Singularity Hub [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Report: AMD Ryzen Performance in Ashes of the Singularity Benchmark - PC Perspective [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Do you believe in the Singularity? - Patheos (blog) [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Editorial Note From the Singularity Hub Team - Singularity Hub [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Discover the Most Advanced Industrial Technologies at Exponential Manufacturing - Singularity Hub [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- 10th Letter looks at nature in the time of the Singularity - Creative Loafing Atlanta [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Donald Trump Is the Singularity - Bloomberg View - Bloomberg.com - Bloomberg [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Wearable Devices Can Actually Tell When You're About to Get Sick - Singularity Hub [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- AMD 8-core Ryzen benchmark show up on Ashes Of The Singularity ... - VR-Zone [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Robot Cars Can Teach Themselves How to Drive in Virtual Worlds - Singularity Hub [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Physicists Unveil Blueprint for a Quantum Computer the Size of a Soccer Field - Singularity Hub [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- How Robots Helped Create 100000 Jobs at Amazon - Singularity Hub [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Ready to Change the World? Apply Now for Singularity University's 2017 Global Solutions Program - Singularity Hub [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Singularity Containers for Science, Reproducibility, and HPC - Linux.com (blog) [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Families Finally Hear From Completely Paralyzed Patients Via New Mind-Reading Device - Singularity Hub [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- artificial intelligence: the fear of a technological singularity ... - ETtech.com [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Holograms Aren't The Stuff of Science Fiction Anymore - Singularity Hub [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- How the World Has Changed From 1917 to 2017 - Singularity Hub [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- Preparing for the Singularity - Inverse [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- Our Health Data Can Save Lives, But We Have to Be Willing to Share - Singularity Hub [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- Ashes of the Singularity merges with standalone expansion Escalation, no upgrade fee - PCGamesN [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- Just Stand Inside this Room and it Will Wirelessly Charge Your Phone - Singularity Hub [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- AMD bundles Ashes of the Singularity with FX processors ahead of Ryzen's launch - PCWorld [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- Ashes of the Singularity: Escalation being merged with the original game - PC Invasion (blog) [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- Singularity - GameSpot [Last Updated On: February 20th, 2017] [Originally Added On: February 20th, 2017]
- The roots of technological singularity can be traced backed to the Stone Age - Wired.co.uk [Last Updated On: February 20th, 2017] [Originally Added On: February 20th, 2017]
- Jide's new OS is like an Android version of Windows 10's Continuum - The Verge [Last Updated On: February 22nd, 2017] [Originally Added On: February 22nd, 2017]
- Jide Announces Remix Singularity: The Continuum Alternative for Android - XDA Developers (blog) [Last Updated On: February 22nd, 2017] [Originally Added On: February 22nd, 2017]
- New Tech Makes Brain Implants Safer and Super Precise - Singularity Hub [Last Updated On: February 23rd, 2017] [Originally Added On: February 23rd, 2017]
- One Android company wants to use smartphones to make PCs truly dead - BGR [Last Updated On: February 23rd, 2017] [Originally Added On: February 23rd, 2017]
- Remix tries its hand at the mobile-desktop hybrid OS with Singularity - Android Police [Last Updated On: February 23rd, 2017] [Originally Added On: February 23rd, 2017]
- Financial Leaders: Make Your Mark on the Future at Exponential Finance - Singularity Hub [Last Updated On: February 23rd, 2017] [Originally Added On: February 23rd, 2017]
- Remix Singularity is Jide's Android answer to Windows Continuum - SlashGear [Last Updated On: February 24th, 2017] [Originally Added On: February 24th, 2017]
- AMD Radeon RX 580 Ashes of the Singularity Benchmarks Leaked 4K, Ryzen Combo, CrossFire and More! - Wccftech [Last Updated On: February 24th, 2017] [Originally Added On: February 24th, 2017]
- Damon Wayans Jr. Joins FX Sci-Fi Comedy Singularity - Den of Geek US [Last Updated On: February 24th, 2017] [Originally Added On: February 24th, 2017]
- After Man? From Singularity to Specificity - Peace Research Institute Oslo (PRIO) (press release) (blog) [Last Updated On: February 24th, 2017] [Originally Added On: February 24th, 2017]
- Why the Potential of Augmented Reality Is Greater Than You Think - Singularity Hub [Last Updated On: February 24th, 2017] [Originally Added On: February 24th, 2017]
- Damon Wayans Jr In Evan Goldberg & Seth Rogen AI comedy - /FILM [Last Updated On: February 24th, 2017] [Originally Added On: February 24th, 2017]
- Ashes of Singularity: Escalation Gets an Update - CGMagazine [Last Updated On: February 24th, 2017] [Originally Added On: February 24th, 2017]
- Google Updates: Scuba, Singularity, SMS and suing - The INQUIRER [Last Updated On: February 24th, 2017] [Originally Added On: February 24th, 2017]
- Singularity Art Show Tonight In San Francisco! [Last Updated On: February 25th, 2017] [Originally Added On: February 25th, 2017]
- Stardock celebrate v2.1 of Ashes of the Singularity: Escalation with a ... - PCGamesN [Last Updated On: February 27th, 2017] [Originally Added On: February 27th, 2017]
- Video: AI Is Getting Smarter, Says Singularity University's Neil ... - Wall Street Journal (subscription) (blog) [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- This Neural Probe Is So Thin, The Brain Doesn't Know It's There - Singularity Hub [Last Updated On: March 1st, 2017] [Originally Added On: March 1st, 2017]
- Citizen Science Means Anyone Could Discover Planet NineEven You - Singularity Hub [Last Updated On: March 1st, 2017] [Originally Added On: March 1st, 2017]
- Singularity University establishes new organisation in Denmark - Ministry of Foreign Affairs of Denmark [Last Updated On: March 1st, 2017] [Originally Added On: March 1st, 2017]
- Singularity University opening organisation in Denmark - The Copenhagen Post - Danish news in english [Last Updated On: March 1st, 2017] [Originally Added On: March 1st, 2017]
- Does Zapping Your Brain Actually Help You Learn Faster? - Singularity Hub [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- What You Need to Know About Elon Musk's Plan to Fly People to the Moon - Singularity Hub [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Singularity: Explain It to Me Like I'm 5-Years-Old - Futurism - Futurism [Last Updated On: March 3rd, 2017] [Originally Added On: March 3rd, 2017]
- Singularity for PC Reviews - Metacritic [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- Singularity (mathematics) - Wikipedia [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- See How This House Was 3D Printed in Just 24 Hours - Singularity Hub [Last Updated On: March 6th, 2017] [Originally Added On: March 6th, 2017]
- NYC's Metrograph theater is running a sci-fi film series featuring Blade Runner, Ex Machina, and Metropolis - The Verge [Last Updated On: March 8th, 2017] [Originally Added On: March 8th, 2017]
- 3 Exciting Biotech Trends to Watch Closely in 2017 - Singularity Hub [Last Updated On: March 9th, 2017] [Originally Added On: March 9th, 2017]
- New Burger Robot Will Take Command of the Grill in 50 Fast Food Restaurants - Singularity Hub [Last Updated On: March 9th, 2017] [Originally Added On: March 9th, 2017]
- Are These Giant Neurons the Seat Of Consciousness in the Brain? - Singularity Hub [Last Updated On: March 10th, 2017] [Originally Added On: March 10th, 2017]
- How Fully Synthetic Complex Life Just Got a Lot Closer - Singularity Hub [Last Updated On: March 12th, 2017] [Originally Added On: March 12th, 2017]
- Singularity University launches inaugural Canada Summit | BetaKit - BetaKit [Last Updated On: April 8th, 2017] [Originally Added On: April 8th, 2017]
- Singularity - Everything2.com [Last Updated On: April 8th, 2017] [Originally Added On: April 8th, 2017]
- Singularity (Game) - Giant Bomb [Last Updated On: April 8th, 2017] [Originally Added On: April 8th, 2017]
- Ashes of the Singularity: Escalation on Steam [Last Updated On: April 8th, 2017] [Originally Added On: April 8th, 2017]
- Approaching the World of Collaboration Singularity - CommsTrader [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Berkeley Lab's Open-Source Spinoff Serves Science | Berkeley Lab - Lawrence Berkeley National Laboratory [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Beyond Politics: Innovating for a Sustainable Future - Singularity Hub [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Tune Into the Future of Fintech at Exponential Finance This Week - Singularity Hub [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Experts Weigh in on AI and the Singularity - Futurism [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Singularity | Mass Effect Wiki | Fandom powered by Wikia [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Quantum Computers Will Analyze Every Financial Model at Once - Singularity Hub [Last Updated On: June 8th, 2017] [Originally Added On: June 8th, 2017]
- Deloitte and Singularity University Extend Their Relationship To ... - PR Newswire (press release) [Last Updated On: June 8th, 2017] [Originally Added On: June 8th, 2017]
- Ashes of the Singularity: Escalation 2.3 update adds a new campaign today - PC Gamer [Last Updated On: June 8th, 2017] [Originally Added On: June 8th, 2017]
- Singularity and Docker | Singularity [Last Updated On: June 8th, 2017] [Originally Added On: June 8th, 2017]
- Ashes of the Singularity gets a new fully-voiced campaign - PCGamesN [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- At Exponential Finance, the Singularity University Explores Visionary Applications of Blockchains - Crypto Insider (press release) (blog) [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Get It While It's Hot: Why Fintech Is a Goldmine for Investors - Singularity Hub [Last Updated On: June 10th, 2017] [Originally Added On: June 10th, 2017]
- Forget Police Sketches: Researchers Perfectly Reconstruct Faces by Reading Brainwaves - Singularity Hub [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Singularity Summit comes to SA | IT-Online - IT-Online [Last Updated On: June 16th, 2017] [Originally Added On: June 16th, 2017]
- These 7 Disruptive Technologies Could Be Worth Trillions of Dollars - Singularity Hub [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]