Can ADRA NDR devices detect and respond to EternalBlue exploits?
Applicable Products
ADRA NDR Appliances
Overview
The EternalBlue exploit (MS17-010) is a series of Windows vulnerabilities that impact services using the Server Message Block version 1 (SMBv1) protocol on a Windows device.
EternalBlue is a self-propagating Windows vulnerability that affects most versions of Windows that haven't been patched. The ransomware targets files that use the SMB v1 protocol by utilizing techniques such as buffer overflow and heap spray to get into a Windows PC on a local network. The initial attack is followed by implanting and propagating malicious software such as Bad Rabbit, NotPetya, and WannaCry. These ransomwares and their variants target vulnerable devices by encrypting the files on the device and then demand ransom payments in return.
Details
ADRA NDR devices can immediately detect the lateral movements of the EternalBlue exploit and secure the network before the exploit migrates to other Windows devices. When detected, the ADRA NDR sends a high-risk threat notification to network administrators before the ransomware implants itself and spreads to other Windows or SMBv1-enabled devices within the network. This alert includes information that network administrators can use to identify, quarantine, and patch the exposed devices.
If the EternalBlue exploit can't be resolved immediately, network administrators can limit the spread by using the ADRA NDR to quarantine the exposed device. This can help avoid ransomware and malicious attack tools from being implanted on the exposed device.