HackTool - SysmonEOP Execution

 Original Source: [Sigma source]
Title: HackTool - SysmonEOP Execution
Status: test
Description:Detects the execution of the PoC that can be used to exploit Sysmon CVE-2022-41120
References:
  -https://github.com/Wh04m1001/SysmonEoP
Author: Florian Roth (Nextron Systems)
Date: 2022-12-04
modified:2024-11-23
Tags:
  • -'cve.2022-41120'
  • -'attack.t1068'
  • -'attack.privilege-escalation'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    Image|endswith: '\SysmonEOP.exe'
  selection_hash:
    Hashes|contains:
      -'IMPHASH=22F4089EB8ABA31E1BB162C6D9BF72E5'
      -'IMPHASH=5123FA4C4384D431CD0D893EEB49BBEC'

  condition:1 of selection_*
Falsepositives:
  -Unlikely
Level: critical