Title:
New Port Forwarding Rule Added Via Netsh.EXE
Status:
test
Description:Detects the execution of netsh commands that configure a new port forwarding (PortProxy) rule
References:
-https://www.fireeye.com/blog/threat-research/2019/01/bypassing-network-restrictions-through-rdp-tunneling.html
-https://adepts.of0x.cc/netsh-portproxy-code/
-https://www.dfirnotes.net/portproxy_detection/
Author: Florian Roth (Nextron Systems), omkar72, oscd.community, Swachchhanda Shrawan Poudel
Date: 2019-01-29
modified:2023-09-01
Tags:
- -'attack.lateral-movement'
- -'attack.command-and-control'
- -'attack.t1090'
Logsource:
- category: process_creation
- product: windows
Detection:
selection_img:
Image|endswith:
'\netsh.exe'
OriginalFileName:
'netsh.exe'
selection_cli_1:
CommandLine|contains|all:
-'interface'
-'portproxy'
-'add'
-'v4tov4'
selection_cli_2:
CommandLine|contains|all:
-'i '
-'p '
-'a '
-'v '
selection_cli_3:
CommandLine|contains|all:
-'connectp'
-'listena'
-'c='
condition:
selection_img and 1 of selection_cli_*
Falsepositives:
-Legitimate administration activity
-WSL2 network bridge PowerShell script used for WSL/Kubernetes/Docker (e.g. https://github.com/microsoft/WSL/issues/4150#issuecomment-504209723)
Level:
medium