This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
PUA - Chisel Tunneling Tool Execution
Original Source:
[Sigma source]
Title:
PUA - Chisel Tunneling Tool Execution
Status:
test
Description:
Detects usage of the Chisel tunneling tool via the commandline arguments
References:
-https://github.com/jpillora/chisel/
-https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in/
-https://blog.sekoia.io/lucky-mouse-incident-response-to-detection-engineering/
Author:
Florian Roth (Nextron Systems)
Date:
2022-09-13
modified:
2023-02-13
Tags:
-'attack.command-and-control'
-'attack.t1090.001'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\chisel.exe'
selection_param1:
CommandLine|contains
:
-'exe client '
-'exe server '
selection_param2:
CommandLine|contains
:
-'-socks5'
-'-reverse'
-' r:'
-':127.0.0.1:'
-'-tls-skip-verify '
-':socks'
condition
:
selection_img or all of selection_param*
Falsepositives:
-Some false positives may occur with other tools with similar commandlines
Level:
high