À la demande de la Direction des Systèmes d'Information de Meridian Finance, Odonia Cyber a conduit une campagne de threat hunting proactif "à l'aveugle" (sans indicateur de compromission fourni au préalable), sur une période analysée du 10 au 17 juin 2026. L'objectif était de répondre à une question simple posée par le DSI : "avons-nous été compromis, et si oui par où ?" Six sources de télémétrie ont été analysées (journaux Windows Security, Sysmon, PowerShell Script Block Logging, connexions Microsoft Entra ID, proxy sortant, inventaire des hôtes), couvrant un périmètre d'environ 120 postes de travail sur le domaine meridian-finance.lan, dont 7 hôtes disposaient d'une télémétrie exploitable.
helpdesk_svc) créé sur le serveur SRV-FILE02. Les TTPs identifiés couvrent les tactiques MITRE ATT&CK TA0001 (Initial Access), TA0003 (Persistence), TA0004/TA0006 (Credential Access), TA0008 (Lateral Movement), TA0009 (Collection) et TA0010 (Exfiltration). Une action d'endiguement immédiate est requise, décrite en Section 3 du rapport narratif associé.
| Source | Type | Volume / Période | Couverture |
|---|---|---|---|
Windows Security Eventswinsec_security.jsonl | Journaux d'événements Windows (EID 4624/4625/4672/4720/4768/4769) | 1 526 événements · 10/06 07:06 UTC → 16/06 19:55 UTC | Complète |
Sysmonsysmon.jsonl | Télémétrie process/réseau/registre (EID 1/3/12/13) | 1 175 événements · 10/06 07:01 UTC → 16/06 19:58 UTC | Complète |
PowerShell Script Block Loggingpowershell_4104.jsonl | Logs d'exécution de scripts PowerShell (EID 4104) | 2 événements · 13/06 10:42 UTC → 10:51 UTC | Partielle |
Microsoft Entra ID sign-insentra_signin.jsonl | Journaux de connexion cloud (M365/Entra ID) | 554 événements · 10/06 07:13 UTC → 16/06 19:54 UTC | Complète |
Proxy sortantproxy.log | Journaux de trafic web sortant (format CLF) | 3 399 lignes · 10/06 07:01 UTC → 16/06 19:58 UTC | Complète |
Inventaire hôteshosts_inventory.csv | Référentiel des systèmes analysés | 7 hôtes · état à la date de collecte | Complète |
| ID | Hypothèse / Cible | Résultat | IOC positifs | Impact |
|---|---|---|---|---|
H-01 | Accès initial : macro Office → PowerShell encodé | Positif | 2 | Critique |
H-02 | Exécution fileless (téléchargement en mémoire) | Positif | 1 | Haute |
H-03 | Beaconing C2 régulier vers domaine externe | Positif | 3 | Critique |
H-04 | Persistance : clé de registre Run masquée | Positif | 1 | Haute |
H-05 | Persistance : tâche planifiée masquée | Positif | 1 | Haute |
H-06 | MFA fatigue et accès cloud M365/Entra ID | Positif | 1 | Critique |
H-07 | Reconnaissance interne / découverte AD | Positif | 0 | Moyenne |
H-08 | Dump mémoire LSASS (vol d'identifiants) | Positif | 1 | Critique |
H-09 | Kerberoasting de comptes de service (RC4) | Positif | 3 | Haute |
H-10 | Mouvement latéral Pass-the-Hash (NTLM) | Positif | 1 | Critique |
H-11 | Création de compte de porte dérobée | Positif | 1 | Critique |
H-12 | Staging et exfiltration de données Finance | Positif | 1 | Critique |
H-13 | Brute force d'authentification locale (on-prem) | Négatif | 0 | · |
H-14 | Trafic proxy anormal vers domaines externes | Négatif | 0 | · |
H-15 | Connexions à risque géographique | Négatif | 0 | · |
H-16 | Lignées de processus bureautiques suspectes | Négatif | 0 | · |
H-17 | Activité anormale de comptes de service (baseline) | Négatif | 0 | · |
WINWORD.EXE → powershell.exe · anomalie de lignée-nop -w hidden -enc · encodage de commande malveillantWKS-FIN-014 (10.20.4.14) · MERIDIAN\a.moreauSysmon EID1 · 2026-06-13 10:42:11 UTC ParentImage=WINWORD.EXE → Image=powershell.exe CommandLine contient : -nop -w hidden -enc [payload base64]
New-Object Net.WebClient;DownloadString(...)|IEX · cradle de téléchargement filelessWKS-FIN-014odsync.exe, sans trace de fichier initial capturéecdn-telemetry-sync.net · domaine C2 et exfiltration193.42.59.114:443 · IP serveur C2Mozilla/5.0 (Windows NT 10.0) · User-Agent constant sur 950 requêtesWKS-FIN-014, SRV-FILE02Proxy : 950 requêtes CONNECT vers cdn-telemetry-sync.net:443 Intervalle moyen : 300 s · coefficient de variation : 0.057 Activité 24h/24 confirmée · dernière communication : 2026-06-16 17:56:47 UTC
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OneDriveSync = %APPDATA%\odsync.exeWKS-FIN-014schtasks.exe /create /sc minute /mo 30 · tâche "OneDrive Sync"WKS-FIN-01445.137.21.88 (Bucarest, Roumanie) · IP source du contournement MFAa.moreau@meridian-finance.lanEntra sign-in logs · 2026-06-14 06:50:00 à 06:51:20 UTC 9 x errorCode 500121 en 80 secondes, puis errorCode 0 (succès) Baseline : 544 des 554 connexions proviennent de Rouen (FR)
whoami /groups · net group "Domain Admins" /domain · nltest /dclist:meridianWKS-FIN-014rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump 672 C:\Temp\lsass.dmp fullWKS-FIN-014Sysmon EID1 · 2026-06-14 09:17:36 UTC Parent : powershell.exe · rundll32.exe exécuté hors C:\Windows\System32 (copie frauduleuse)
MSSQLSvc/srv-app03.meridian-finance.lanHTTP/srv-app03CIFS/srv-file02DC02 (requête source 10.20.4.14)winsec EID 4769 x3 · 2026-06-14 09:40:00 à 09:40:06 UTC TicketEncryptionType 0x17 (RC4) · 3 SPN distincts en 6 secondes
svc_sched à considérer comme compromis (craquage hors ligne possible)svc_sched · IpAddress 10.20.4.14SRV-FILE02winsec · 2026-06-15 14:22:00 UTC Seul logon NTLM cross-segment observé sur 21 logons de svc_sched depuis 10.20.4.14 (20 logons Kerberos légitimes, 1 logon NTLM anormal vers SRV-FILE02)
svc_schedsvc_sched · TargetUserName=helpdesk_svcSRV-FILE02winsec EID 4720 · 2026-06-15 14:22:02 UTC (2 s après le pivot latéral H-10)
C:\Temp\fin.rar · archive RAR chiffrée par mot de passe (flag -hp)SRV-FILE02Sysmon EID1 · 2026-06-16 02:13:00 UTC rar.exe a -hp C:\Temp\fin.rar \\srv-file02\Finance\*.xlsx Proxy · 2026-06-16 02:17:00 UTC · CONNECT cdn-telemetry-sync.net:443 · sc_bytes=58 879 805
Les cinq chasses suivantes ont été menées jusqu'à leur terme et n'ont révélé aucune activité malveillante. Elles constituent le calibrage du bruit de fond légitime et ont permis, par contraste, de faire ressortir les anomalies retenues ci-dessus (voir Section 4.5 du rapport narratif pour le détail complet).
Les techniques détectées ont été mappées sur le référentiel MITRE ATT&CK Enterprise v14. Ce mapping permet d'identifier le profil de l'attaquant et les phases de l'attaque, de l'accès initial jusqu'à l'exfiltration.
| Tactique (TA) | Technique (T) | Sous-technique | Preuve | Criticité |
|---|---|---|---|---|
| Initial Access TA0001 | Spearphishing Attachment | T1566.001 | H-01 | Critique |
| Execution TA0002 | PowerShell / User Execution | T1059.001 / T1204.002 | H-01, H-02 | Critique |
| Command and Control TA0011 | Application Layer Protocol / Encrypted Channel | T1071.001 / T1573 | H-03 | Critique |
| Persistence TA0003 | Registry Run Keys / Scheduled Task | T1547.001 / T1053.005 | H-04, H-05 | Haute |
| Credential Access TA0006 | MFA Request Generation | T1621 | H-06 | Critique |
| Discovery TA0007 | System/Account/Domain Trust Discovery | T1033 / T1087.002 / T1482 | H-07 | Moyenne |
| Credential Access TA0006 | OS Credential Dumping (LSASS) | T1003.001 | H-08 | Critique |
| Credential Access TA0006 | Steal or Forge Kerberos Tickets (Kerberoasting) | T1558.003 | H-09 | Haute |
| Lateral Movement TA0008 | Use Alternate Auth. Material (Pass-the-Hash) | T1550.002 / T1021.002 | H-10 | Critique |
| Persistence TA0003 | Create Account (Local Account) | T1136.001 | H-11 | Critique |
| Collection TA0009 | Archive Collected Data / Data from Network Share | T1560.001 / T1039 / T1074 | H-12 | Critique |
| Exfiltration TA0010 | Exfiltration Over C2 Channel / to Cloud Storage | T1041 / T1567 | H-12 | Critique |
Les TTPs identifiés (macro Office avec commande PowerShell encodée, MFA fatigue, dump LSASS via comsvcs, Kerberoasting en RC4, Pass-the-Hash, exfiltration compressée chiffrée vers un canal C2 HTTPS) correspondent au profil d'un attaquant de type cybercriminel opportuniste à intermédiaire, dont le mode opératoire est cohérent avec une chaîne de double extorsion : vol de données financières précédant potentiellement un déploiement de rançongiciel. Aucune attribution à un groupe APT spécifique n'est possible avec les seules données de télémétrie disponibles (aucun hash de fichier collecté, investigation menée à distance sans accès filesystem). Une analyse forensique complète des deux hôtes impactés (Action 10 du plan de remédiation) est nécessaire pour affiner cette attribution.
| Priorité | Action | Hunt adressé | Responsable | Délai |
|---|---|---|---|---|
| Immédiate | Isoler WKS-FIN-014 et SRV-FILE02, révoquer les comptes compromis, supprimer helpdesk_svc | H-01, H-10, H-11 | DSI Meridian Finance | 0 à 24 heures |
| Court terme | Réinitialiser krbtgt deux fois, effectuer la rotation des comptes de service, forensique complète | H-09, H-10 | DSI + prestataire DFIR | 30 jours |
| Moyen terme | Déployer un EDR, MFA Number Matching, désactiver RC4, modèle de tiering AD | Global | DSI Meridian Finance | 90 jours |
Treize règles Sigma ont été rédigées à partir des techniques observées lors de cette investigation (référence mf-2026-001-01 à mf-2026-001-13), prêtes à être déployées dans un SIEM compatible (Microsoft Sentinel, Elastic SIEM, Splunk). Le catalogue complet des 13 règles est livré séparément dans le livret Sigma dédié à cette mission. Les quatre règles couvrant les techniques les plus critiques sont reproduites ci-dessous à titre d'illustration.
title: Office Application Spawns PowerShell with Encoded Command
id: mf-2026-001-01
status: experimental
logsource:
product: windows
category: process_creation
detection:
parent:
ParentImage|endswith:
- '\WINWORD.EXE'
- '\EXCEL.EXE'
- '\POWERPNT.EXE'
- '\OUTLOOK.EXE'
child:
Image|endswith: '\powershell.exe'
flags:
CommandLine|contains|all:
- '-enc'
- '-w hidden'
condition: parent and child and flags
level: high
title: LSASS Memory Dump via comsvcs MiniDump
id: mf-2026-001-04
status: experimental
logsource:
product: windows
category: process_creation
detection:
sel:
CommandLine|contains|all:
- 'comsvcs.dll'
- 'MiniDump'
condition: sel
level: critical
title: MFA Fatigue - Repeated Denials Followed by Immediate Success
id: mf-2026-001-06
status: experimental
logsource:
product: azure
service: signinlogs
detection:
fail:
Status.errorCode: 500121
success:
Status.errorCode: 0
timeframe: 10m
condition: fail | count() by UserPrincipalName >= 5 and success
level: high
title: Lateral Movement - NTLM Network Logon from Workstation to Server (Pass-the-Hash Signature)
id: mf-2026-001-13
status: experimental
logsource:
product: windows
service: security
detection:
sel:
EventID: 4624
LogonType: 3
AuthenticationPackageName: 'NTLM'
TargetUserName|startswith: 'svc_'
src:
IpAddress|startswith: '10.20.4.'
dst:
Computer|startswith:
- 'SRV-'
- 'DC0'
condition: sel and src and dst
level: high
| Type | Valeur | Hunt | Confiance |
|---|---|---|---|
| Domaine C2/exfiltration | cdn-telemetry-sync.net | H-03, H-12 | Haute |
| IP serveur C2 | 193.42.59.114:443 | H-03 | Haute |
| IP attaquant cloud | 45.137.21.88 (Bucarest, RO) | H-06 | Haute |
| User-Agent C2 | Mozilla/5.0 (Windows NT 10.0) | H-03 | Moyenne |
| Hôte patient zéro | WKS-FIN-014 (10.20.4.14) | H-01, H-02, H-07, H-08, H-09 | Haute |
| Hôte exfiltration | SRV-FILE02 (10.20.1.12) | H-10, H-11, H-12 | Haute |
| Compte initial compromis | MERIDIAN\a.moreau | H-01, H-06 | Haute |
| Compte de service pivot | MERIDIAN\svc_sched | H-09, H-10 | Haute |
| Compte backdoor créé | helpdesk_svc | H-11 | Haute |
| Implant C2 | C:\Users\a.moreau\AppData\Roaming\odsync.exe | H-02, H-04 | Haute |
| Binaire système détourné | C:\Users\a.moreau\AppData\Local\Temp\rundll32.exe | H-08 | Haute |
| Dump mémoire LSASS | C:\Temp\lsass.dmp | H-08 | Haute |
| Archive exfiltrée | C:\Temp\fin.rar | H-12 | Haute |
| Clé de registre persistance | HKCU\...\Run\OneDriveSync | H-04 | Haute |
| Tâche planifiée persistance | "OneDrive Sync" (/sc minute /mo 30) | H-05 | Haute |
| SPN kerberoastés | MSSQLSvc/srv-app03, HTTP/srv-app03, CIFS/srv-file02 | H-09 | Haute |
// KQL - Microsoft Sentinel - proxy CommonSecurityLog CommonSecurityLog | where DestinationHostName == "cdn-telemetry-sync.net" | summarize count(), avg(TimeGenerated - prev(TimeGenerated)) by SourceIP, bin(TimeGenerated, 1h) | where count_ > 20 | project SourceIP, RequestCount = count_, AvgIntervalSeconds = avg_TimeGenerated
// KQL - Microsoft Sentinel - SecurityEvent SecurityEvent | where EventID == 4624 and LogonType == 3 | where AuthenticationPackageName == "NTLM" | where TargetUserName startswith "svc_" | where IpAddress startswith "10.20.4." | project TimeGenerated, TargetUserName, IpAddress, Computer
| Timestamp (UTC) | Hôte | Événement | Hunt |
|---|---|---|---|
2026-06-13 10:42:11 | WKS-FIN-014 | Macro Word lance PowerShell encodé en mémoire | H-01 |
2026-06-13 10:42:12 | WKS-FIN-014 | Téléchargement et exécution fileless (IEX) | H-02 |
2026-06-13 10:42:41 | WKS-FIN-014 | Début du beaconing C2 (toutes les 300 s) | H-03 |
2026-06-13 10:51:11 | WKS-FIN-014 | Persistance : clé de registre Run "OneDriveSync" | H-04 |
2026-06-13 10:51:31 | WKS-FIN-014 | Persistance : tâche planifiée "OneDrive Sync" | H-05 |
2026-06-14 06:50:00 → 06:51:20 | Cloud Entra ID | MFA fatigue : 9 pushs en 80 s puis approbation, accès M365 obtenu | H-06 |
2026-06-14 09:15:00 → 09:15:24 | WKS-FIN-014 | Découverte interne : whoami, groupes AD, nltest | H-07 |
2026-06-14 09:17:36 | WKS-FIN-014 | Dump LSASS via comsvcs MiniDump | H-08 |
2026-06-14 09:40:00 → 09:40:06 | DC02 | Kerberoasting de 3 SPN en RC4 | H-09 |
2026-06-15 14:22:00 | SRV-FILE02 | Mouvement latéral Pass-the-Hash (NTLM) | H-10 |
2026-06-15 14:22:02 | SRV-FILE02 | Création du compte backdoor "helpdesk_svc" | H-11 |
2026-06-16 02:13:00 | SRV-FILE02 | Staging : archive RAR chiffrée du partage Finance | H-12 |
2026-06-16 02:17:00 | SRV-FILE02 | Exfiltration de 58,8 Mo vers cdn-telemetry-sync.net | H-12 |
Dernière communication C2 observée : 2026-06-16 17:56:47 UTC. La compromission était toujours active en fin de fenêtre d'analyse.
| Fichier | SHA-256 | Date |
|---|---|---|
rapport_threat_hunting.pdf | à calculer lors de l'export PDF final | 1er juillet 2026 |
remediation_plan.html | à calculer lors de l'export PDF final | 1er juillet 2026 |
Contact : odonia.fr · Normandie (Caen / Flers) · ODN-2026-007 / MF-2026-001