Suspicious PowerShell Parent Process

 Original Source: [Sigma source]
Title: Suspicious PowerShell Parent Process
Status: test
Description:Detects a suspicious or uncommon parent processes of PowerShell
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=26
Author: Teymur Kheirkhabarov, Harish Segar
Date: 2020-03-20
modified:2023-02-04
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_parent:
ParentImage|contains:'tomcat'     - ParentImage|endswith:
      - '\amigo.exe'
      - '\browser.exe'
      - '\chrome.exe'
      - '\firefox.exe'
      - '\httpd.exe'
      - '\iexplore.exe'
      - '\jbosssvc.exe'
      - '\microsoftedge.exe'
      - '\microsoftedgecp.exe'
      - '\MicrosoftEdgeSH.exe'
      - '\mshta.exe'
      - '\nginx.exe'
      - '\outlook.exe'
      - '\php-cgi.exe'
      - '\regsvr32.exe'
      - '\rundll32.exe'
      - '\safari.exe'
      - '\services.exe'
      - '\sqlagent.exe'
      - '\sqlserver.exe'
      - '\sqlservr.exe'
      - '\vivaldi.exe'
      - '\w3wp.exe'
  selection_powershell:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    - CommandLine|contains:
      - '/c powershell'
      - '/c pwsh'
Description:'Windows PowerShell' Product:'PowerShell Core 6'     - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  condition:all of selection_*
Falsepositives:
  -Other scripts
Level: high