Hacktool Execution - PE Metadata

 Original Source: [Sigma source]
Title: Hacktool Execution - PE Metadata
Status: test
Description:Detects the execution of different Windows based hacktools via PE metadata (company, product, etc.) even if the files have been renamed
References:
  -https://github.com/cube0x0
  -https://www.virustotal.com/gui/search/metadata%253ACube0x0/files
Author: Florian Roth (Nextron Systems)
Date: 2022-04-27
modified:2024-01-15
Tags:
  • -'attack.credential-access'
  • -'attack.resource-development'
  • -'attack.t1588.002'
  • -'attack.t1003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Company: 'Cube0x0'
  condition:selection
Falsepositives:
  -Unlikely
Level: high