Potential Reconnaissance Activity Via GatherNetworkInfo.VBS

 Original Source: [Sigma source]
Title: Potential Reconnaissance Activity Via GatherNetworkInfo.VBS
Status: test
Description:Detects execution of the built-in script located in "C:\Windows\System32\gatherNetworkInfo.vbs". Which can be used to gather information about the target machine
References:
  -https://posts.slayerlabs.com/living-off-the-land/#gathernetworkinfovbs
  -https://www.mandiant.com/resources/blog/trojanized-windows-installers-ukrainian-government
Author: blueteamer8699
Date: 2022-01-03
modified:2023-02-08
Tags:
  • -'attack.discovery'
  • -'attack.execution'
  • -'attack.t1615'
  • -'attack.t1059.005'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\cscript.exe'
      - '\wscript.exe'
    - OriginalFileName:
      - 'cscript.exe'
      - 'wscript.exe'
  selection_cli:
    CommandLine|contains: 'gatherNetworkInfo.vbs'
  condition:all of selection_*
Falsepositives:
  -Administrative activity
Level: medium