Title:Potential Arbitrary Command Execution Via FTP.EXE Status:test Description:Detects execution of "ftp.exe" script with the "-s" or "/s" flag and any child processes ran by "ftp.exe". References: -https://lolbas-project.github.io/lolbas/Binaries/Ftp/ Author: Victor Sergeev, oscd.community Date: 2020-10-09 modified:2024-04-23 Tags:
-'attack.execution'
-'attack.stealth'
-'attack.t1059'
-'attack.t1202'
Logsource:
category: process_creation
product: windows
Detection: selection_parent: ParentImage|endswith:
'\ftp.exe' selection_child_img: Image|endswith:'\ftp.exe'OriginalFileName:'ftp.exe'selection_child_cli: CommandLine|contains|windash:
'-s:' condition:selection_parent or all of selection_child_* Falsepositives:
-Unknown Level:medium