This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential Manage-bde.wsf Abuse To Proxy Execution
Original Source:
[Sigma source]
Title:
Potential Manage-bde.wsf Abuse To Proxy Execution
Status:
test
Description:
Detects potential abuse of the "manage-bde.wsf" script as a LOLBIN to proxy execution
References:
-https://lolbas-project.github.io/lolbas/Scripts/Manage-bde/
-https://gist.github.com/bohops/735edb7494fe1bd1010d67823842b712
-https://twitter.com/bohops/status/980659399495741441
-https://twitter.com/JohnLaTwC/status/1223292479270600706
-https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1216/T1216.md
Author:
oscd.community, Natalia Shornikova, Nasreddine Bencherchali (Nextron Systems)
Date:
2020-10-13
modified:
2023-02-03
Tags:
-'attack.stealth'
-'attack.t1216'
Logsource:
category: process_creation
product: windows
Detection:
selection_wscript_img:
Image|endswith
:
'\wscript.exe'
OriginalFileName
:
'wscript.exe'
selection_wscript_cli:
CommandLine|contains
:
'manage-bde.wsf'
selection_parent:
ParentImage|endswith
:
-'\cscript.exe'
-'\wscript.exe'
ParentCommandLine|contains
:
'manage-bde.wsf'
selection_filter_cmd:
Image|endswith
:
'\cmd.exe'
condition
:
all of selection_wscript_* or (selection_parent and not selection_filter_cmd)
Falsepositives:
-Unlikely
Level:
high