Skip to main content
FSM_FTNT
Staff
Staff
February 15, 2022

Technical Tip: Using FortiSIEM to detect Win32k.sys driver exploit | CVE-2022-21882

  • February 15, 2022
  • 0 replies
  • 603 views
Description This article describes how to use a custom Rules and Reports in FortiSIEM to raise alerts for incident response related to attacks that attempt to exploit a vulnerability in the Win32k.sys driver.
Scope

These Rules and Reports help to detect attempts to gain privilege escalation through an exploit of the Win32k.sys driver based on logs from FortiGates, FortiClients, and FortiProxy.

 

The custom Rules and Reports provided can be used in FortiSIEM 6.x.

 

What is included in: Fortinet_FortiSIEM_Win32k_Privilege_Escalation.zip?

 

1) Fortinet_FortiSIEM_Win32k_Rules_v1.xml

These Rules help identify attacks that attempt to exploit a the vulnerability and are detected by FortiGate, FortiClient and FortiSandbox logs.

 

2) Fortinet_FortiSIEM_Win32k_Report_v1.xml

This report displays attacks that attempt to exploit a the vulnerability and are detected by FortiGate, FortiClient and FortiSandbox logs.

Solution

The exploit allows a locally authenticated attacker to gain elevated local system or administrator privileges.

 

This vulnerability is assigned CVE-2022-21882.

For more information about this attack, see the following FortiGuard Outbreak Alert.

 

1) Download the Fortinet_FortiSIEM_Win32k_Privilege_Escalation.zip(contains 2 file).

 

2) Unzip Fortinet_FortiSIEM_Win32k_Privilege_Escalation.zip

 

3) Use Fortinet_FortiSIEM_Win32k_Report_v1.xml as the file to import the Reports.


- Navigate to Resource / Reports.
- It is recommended to create a new group under Resource / Reports / Security called 'Win32 Priv Escalation' and import reports to this group.


- Select the Import option under More.
- Select Fortinet_FortiSIEM_Win32k_Report_v1.xml and import.

 

4) Use Fortinet_FortiSIEM_Win32k_Rules_v1.xml as the file to import the Rules.


- Navigate to Resource / Rules.
- It is recommended to create a new group under Resource / Rules / Security / Threat Hunting is created called 'Win32 Priv Escalation' and import the rules to this group.


- Select the Import.
- Select Fortinet_FortiSIEM_Win32k_Rules_v1.xml and import.
- Filter the rules for those defined in content pack 101 and ensure they are enabled.

 

https://help.fortinet.com/fsiem/6-4-0/Online-Help/HTML5_Help/content_updates.htm