Process Access via TrolleyExpress Exclusion

 Original Source: [Sigma source]
Title: Process Access via TrolleyExpress Exclusion
Status: test
Description:Detects a possible process memory dump that uses the white-listed Citrix TrolleyExpress.exe filename as a way to dump the lsass process memory
References:
  -https://twitter.com/_xpn_/status/1491557187168178176
  -https://www.youtube.com/watch?v=Ie831jF0bb0
Author: Florian Roth (Nextron Systems)
Date: 2022-02-10
modified:2022-05-13
Tags:
  • -'attack.stealth'
  • -'attack.t1218.011'
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains:
      -'\TrolleyExpress 7'
      -'\TrolleyExpress 8'
      -'\TrolleyExpress 9'
      -'\TrolleyExpress.exe 7'
      -'\TrolleyExpress.exe 8'
      -'\TrolleyExpress.exe 9'
      -'\TrolleyExpress.exe -ma '

  renamed:
    Image|endswith: '\TrolleyExpress.exe'
  filter_renamed:
    OriginalFileName|contains: 'CtxInstall'
  filter_empty:
    OriginalFileName: 'None'
  condition:selection or ( renamed and not 1 of filter* )
Falsepositives:
  -Unknown
Level: high