PUA - Wsudo Suspicious Execution

 Original Source: [Sigma source]
Title: PUA - Wsudo Suspicious Execution
Status: test
Description:Detects usage of wsudo (Windows Sudo Utility). Which is a tool that let the user execute programs with different permissions (System, Trusted Installer, Administrator...etc)
References:
  -https://github.com/M2Team/Privexec/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-12-02
modified:2023-02-14
Tags:
  • -'attack.execution'
  • -'attack.privilege-escalation'
  • -'attack.t1059'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_metadata:
Image|endswith:'\wsudo.exe' OriginalFileName:'wsudo.exe' Description:'Windows sudo utility' ParentImage|endswith:'\wsudo-bridge.exe'   selection_cli:
    CommandLine|contains:
      -'-u System'
      -'-uSystem'
      -'-u TrustedInstaller'
      -'-uTrustedInstaller'
      -' --ti '

  condition:1 of selection_*
Falsepositives:
  -Unknown
Level: high