This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File
Original Source:
[Sigma source]
Title:
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File
Status:
test
Description:
Detects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
References:
-https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404
Author:
Julia Fomina, oscd.community
Date:
2020-10-06
modified:
2022-11-28
Tags:
-'attack.stealth'
-'attack.t1216'
Logsource:
product: windows
category: file_event
Detection:
system_files:
TargetFilename|endswith
:
-'WsmPty.xsl'
-'WsmTxt.xsl'
in_system_folder:
TargetFilename|startswith
:
-'C:\Windows\System32\'
-'C:\Windows\SysWOW64\'
condition
:
system_files and not in_system_folder
Falsepositives:
-Unlikely
Level:
medium