New Network Trace Capture Started Via Netsh.EXE

 Original Source: [Sigma source]
Title: New Network Trace Capture Started Via Netsh.EXE
Status: test
Description:Detects the execution of netsh with the "trace" flag in order to start a network capture
References:
  -https://blogs.msdn.microsoft.com/canberrapfe/2012/03/30/capture-a-network-trace-without-installing-anything-capture-a-network-trace-of-a-reboot/
  -https://klausjochem.me/2016/02/03/netsh-the-cyber-attackers-tool-of-choice/
Author: Kutepov Anton, oscd.community
Date: 2019-10-24
modified:2023-02-13
Tags:
  • -'attack.discovery'
  • -'attack.credential-access'
  • -'attack.t1040'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\netsh.exe' OriginalFileName:'netsh.exe'   selection_cli:
    CommandLine|contains|all:
      -'trace'
      -'start'

  condition:all of selection_*
Falsepositives:
  -Legitimate administration activity
Level: medium