Potential Privilege Escalation Using Symlink Between Osk and Cmd

 Original Source: [Sigma source]
Title: Potential Privilege Escalation Using Symlink Between Osk and Cmd
Status: test
Description:Detects the creation of a symbolic link between "cmd.exe" and the accessibility on-screen keyboard binary (osk.exe) using "mklink". This technique provides an elevated command prompt to the user from the login screen without the need to log in.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/5c1e6f1b4fafd01c8d1ece85f510160fc1275fbf/atomics/T1546.008/T1546.008.md
  -https://ss64.com/nt/mklink.html
Author: frack113
Date: 2022-12-11
modified:2022-12-20
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1546.008'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_img:
Image|endswith:'\cmd.exe' OriginalFileName:'Cmd.Exe'   selection_cli:
    CommandLine|contains|all:
      -'mklink'
      -'\osk.exe'
      -'\cmd.exe'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high