AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File

 Original Source: [Sigma source]
Title: AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File
Status: test
Description:Detects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
References:
  -https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404
Author: Julia Fomina, oscd.community
Date: 2020-10-06
modified:2022-11-28
Tags:
  • -'attack.stealth'
  • -'attack.t1216'
Logsource:
  • product: windows
  • category: file_event
Detection:
  system_files:
    TargetFilename|endswith:
      -'WsmPty.xsl'
      -'WsmTxt.xsl'

  in_system_folder:
    TargetFilename|startswith:
      -'C:\Windows\System32\'
      -'C:\Windows\SysWOW64\'

  condition:system_files and not in_system_folder
Falsepositives:
  -Unlikely
Level: medium