New Port Forwarding Rule Added Via Netsh.EXE

 Original Source: [Sigma source]
Title: New Port Forwarding Rule Added Via Netsh.EXE
Status: test
Description:Detects the execution of netsh commands that configure a new port forwarding (PortProxy) rule
References:
  -https://www.fireeye.com/blog/threat-research/2019/01/bypassing-network-restrictions-through-rdp-tunneling.html
  -https://adepts.of0x.cc/netsh-portproxy-code/
  -https://www.dfirnotes.net/portproxy_detection/
Author: Florian Roth (Nextron Systems), omkar72, oscd.community, Swachchhanda Shrawan Poudel
Date: 2019-01-29
modified:2023-09-01
Tags:
  • -'attack.lateral-movement'
  • -'attack.command-and-control'
  • -'attack.t1090'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\netsh.exe' OriginalFileName:'netsh.exe'   selection_cli_1:
    CommandLine|contains|all:
      -'interface'
      -'portproxy'
      -'add'
      -'v4tov4'

  selection_cli_2:
    CommandLine|contains|all:
      -'i '
      -'p '
      -'a '
      -'v '

  selection_cli_3:
    CommandLine|contains|all:
      -'connectp'
      -'listena'
      -'c='

  condition:selection_img and 1 of selection_cli_*
Falsepositives:
  -Legitimate administration activity
  -WSL2 network bridge PowerShell script used for WSL/Kubernetes/Docker (e.g. https://github.com/microsoft/WSL/issues/4150#issuecomment-504209723)
Level: medium