Suspicious Svchost Process Access

 Original Source: [Sigma source]
Title: Suspicious Svchost Process Access
Status: test
Description:Detects suspicious access to the "svchost" process such as that used by Invoke-Phantom to kill the thread of the Windows event logging service.
References:
  -https://github.com/hlldz/Invoke-Phant0m
  -https://twitter.com/timbmsft/status/900724491076214784
Author: Tim Burrell
Date: 2020-01-02
modified:2023-01-30
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685.001'
Logsource:
  • category: process_access
  • product: windows
Detection:
  selection:
    TargetImage|endswith: ':\Windows\System32\svchost.exe'
    GrantedAccess: '0x1F3FFF'
    CallTrace|contains: 'UNKNOWN'
  filter_main_msbuild:
    SourceImage|contains: ':\Program Files\Microsoft Visual Studio\'
    SourceImage|endswith: '\MSBuild\Current\Bin\MSBuild.exe'
    CallTrace|contains:
      -'Microsoft.Build.ni.dll'
      -'System.ni.dll'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high