This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential Privilege Escalation Using Symlink Between Osk and Cmd
Original Source:
[Sigma source]
Title:
Potential Privilege Escalation Using Symlink Between Osk and Cmd
Status:
test
Description:
Detects the creation of a symbolic link between "cmd.exe" and the accessibility on-screen keyboard binary (osk.exe) using "mklink". This technique provides an elevated command prompt to the user from the login screen without the need to log in.
References:
-https://github.com/redcanaryco/atomic-red-team/blob/5c1e6f1b4fafd01c8d1ece85f510160fc1275fbf/atomics/T1546.008/T1546.008.md
-https://ss64.com/nt/mklink.html
Author:
frack113
Date:
2022-12-11
modified:
2022-12-20
Tags:
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.t1546.008'
Logsource:
product: windows
category: process_creation
Detection:
selection_img:
Image|endswith
:
'\cmd.exe'
OriginalFileName
:
'Cmd.Exe'
selection_cli:
CommandLine|contains|all
:
-'mklink'
-'\osk.exe'
-'\cmd.exe'
condition
:
all of selection_*
Falsepositives:
-Unknown
Level:
high