Visual Studio NodejsTools PressAnyKey Renamed Execution

 Original Source: [Sigma source]
Title: Visual Studio NodejsTools PressAnyKey Renamed Execution
Status: test
Description:Detects renamed execution of "Microsoft.NodejsTools.PressAnyKey.exe", which can be abused as a LOLBIN to execute arbitrary binaries
References:
  -https://twitter.com/mrd0x/status/1463526834918854661
  -https://gist.github.com/nasbench/a989ce64cefa8081bd50cf6ad8c491b5
Author: Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems)
Date: 2023-04-11
modified:None
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    OriginalFileName: 'Microsoft.NodejsTools.PressAnyKey.exe'
  filter_main_legit_name:
    Image|endswith: '\Microsoft.NodejsTools.PressAnyKey.exe'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: medium