Potential DLL Injection Or Execution Using Tracker.exe

 Original Source: [Sigma source]
Title: Potential DLL Injection Or Execution Using Tracker.exe
Status: test
Description:Detects potential DLL injection and execution using "Tracker.exe"
References:
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/
Author: Avneet Singh @v3t0_, oscd.community
Date: 2020-10-18
modified:2023-01-09
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1055.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\tracker.exe' Description:'Tracker'   selection_cli:
    CommandLine|contains:
      -' /d '
      -' /c '

  filter_msbuild1:
    CommandLine|contains: ' /ERRORREPORT:PROMPT '
  filter_msbuild2:
    ParentImage|endswith:
      -'\Msbuild\Current\Bin\MSBuild.exe'
      -'\Msbuild\Current\Bin\amd64\MSBuild.exe'

  condition:all of selection_* and not 1 of filter_*
Falsepositives:
  -Unknown
Level: medium