XBAP Execution From Uncommon Locations Via PresentationHost.EXE

 Original Source: [Sigma source]
Title: XBAP Execution From Uncommon Locations Via PresentationHost.EXE
Status: test
Description:Detects the execution of ".xbap" (Browser Applications) files via PresentationHost.EXE from an uncommon location. These files can be abused to run malicious ".xbap" files any bypass AWL
References:
  -https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-07-01
modified:2023-11-09
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\presentationhost.exe' OriginalFileName:'PresentationHost.exe'   selection_cli:
    CommandLine|contains: '.xbap'
  filter_main_generic:
    CommandLine|contains:
      -' C:\Windows\'
      -' C:\Program Files'

  condition:all of selection* and not 1 of filter_main_*
Falsepositives:
  -Legitimate ".xbap" being executed via "PresentationHost"
Level: medium