This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Uncommon Sigverif.EXE Child Process
Original Source:
[Sigma source]
Title:
Uncommon Sigverif.EXE Child Process
Status:
test
Description:
Detects uncommon child processes spawning from "sigverif.exe", which could indicate potential abuse of the latter as a living of the land binary in order to proxy execution.
References:
-https://www.hexacorn.com/blog/2018/04/27/i-shot-the-sigverif-exe-the-gui-based-lolbin/
-https://twitter.com/0gtweet/status/1457676633809330184
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-08-19
modified:
2024-08-27
Tags:
-'attack.stealth'
-'attack.t1216'
Logsource:
category: process_creation
product: windows
Detection:
selection:
ParentImage|endswith
:
'\sigverif.exe'
filter_main_werfault:
Image
:
-'C:\Windows\System32\WerFault.exe'
-'C:\Windows\SysWOW64\WerFault.exe'
condition
:
selection and not 1 of filter_main_*
Falsepositives:
-Unknown
Level:
medium