Renamed PingCastle Binary Execution

 Original Source: [Sigma source]
Title: Renamed PingCastle Binary Execution
Status: test
Description:Detects the execution of a renamed "PingCastle" binary based on the PE metadata fields.
References:
  -https://thedfirreport.com/2023/10/30/netsupport-intrusion-results-in-domain-compromise/
  -https://www.pingcastle.com/documentation/scanner/
Author: Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems)
Date: 2024-01-11
modified:None
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1059'
  • -'attack.t1202'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    - OriginalFileName:
      - 'PingCastleReporting.exe'
      - 'PingCastleCloud.exe'
      - 'PingCastle.exe'
    - CommandLine|contains:
      - '--scanner aclcheck'
      - '--scanner antivirus'
      - '--scanner computerversion'
      - '--scanner foreignusers'
      - '--scanner laps_bitlocker'
      - '--scanner localadmin'
      - '--scanner nullsession'
      - '--scanner nullsession-trust'
      - '--scanner oxidbindings'
      - '--scanner remote'
      - '--scanner share'
      - '--scanner smb'
      - '--scanner smb3querynetwork'
      - '--scanner spooler'
      - '--scanner startup'
      - '--scanner zerologon'
CommandLine|contains:'--no-enum-limit'     - CommandLine|contains|all:
      - '--healthcheck'
      - '--level Full'
    - CommandLine|contains|all:
      - '--healthcheck'
      - '--server '
  filter_main_img:
    Image|endswith:
      -'\PingCastleReporting.exe'
      -'\PingCastleCloud.exe'
      -'\PingCastle.exe'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high