This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Renamed PingCastle Binary Execution
Original Source:
[Sigma source]
Title:
Renamed PingCastle Binary Execution
Status:
test
Description:
Detects the execution of a renamed "PingCastle" binary based on the PE metadata fields.
References:
-https://thedfirreport.com/2023/10/30/netsupport-intrusion-results-in-domain-compromise/
-https://www.pingcastle.com/documentation/scanner/
Author:
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems)
Date:
2024-01-11
modified:
None
Tags:
-'attack.execution'
-'attack.stealth'
-'attack.t1059'
-'attack.t1202'
Logsource:
category: process_creation
product: windows
Detection:
selection:
- OriginalFileName
:
- 'PingCastleReporting.exe'
- 'PingCastleCloud.exe'
- 'PingCastle.exe'
- CommandLine|contains
:
- '--scanner aclcheck'
- '--scanner antivirus'
- '--scanner computerversion'
- '--scanner foreignusers'
- '--scanner laps_bitlocker'
- '--scanner localadmin'
- '--scanner nullsession'
- '--scanner nullsession-trust'
- '--scanner oxidbindings'
- '--scanner remote'
- '--scanner share'
- '--scanner smb'
- '--scanner smb3querynetwork'
- '--scanner spooler'
- '--scanner startup'
- '--scanner zerologon'
CommandLine|contains
:
'--no-enum-limit'
- CommandLine|contains|all
:
- '--healthcheck'
- '--level Full'
- CommandLine|contains|all
:
- '--healthcheck'
- '--server '
filter_main_img:
Image|endswith
:
-'\PingCastleReporting.exe'
-'\PingCastleCloud.exe'
-'\PingCastle.exe'
condition
:
selection and not 1 of filter_main_*
Falsepositives:
-Unknown
Level:
high