Potential Persistence Via Netsh Helper DLL

 Original Source: [Sigma source]
Title: Potential Persistence Via Netsh Helper DLL
Status: test
Description:Detects the execution of netsh with "add helper" flag in order to add a custom helper DLL. This technique can be abused to add a malicious helper DLL that can be used as a persistence proxy that gets called when netsh.exe is executed.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.007/T1546.007.md
  -https://github.com/outflanknl/NetshHelperBeacon
  -https://web.archive.org/web/20160928212230/https://www.adaptforward.com/2016/09/using-netshell-to-execute-evil-dlls-and-persist-on-a-host/
Author: Victor Sergeev, oscd.community
Date: 2019-10-25
modified:2023-11-28
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1546.007'
  • -'attack.s0108'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
OriginalFileName:'netsh.exe' Image|endswith:'\netsh.exe'   selection_cli:
    CommandLine|contains|all:
      -'add'
      -'helper'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium