Uncommon Sigverif.EXE Child Process

 Original Source: [Sigma source]
Title: Uncommon Sigverif.EXE Child Process
Status: test
Description:Detects uncommon child processes spawning from "sigverif.exe", which could indicate potential abuse of the latter as a living of the land binary in order to proxy execution.
References:
  -https://www.hexacorn.com/blog/2018/04/27/i-shot-the-sigverif-exe-the-gui-based-lolbin/
  -https://twitter.com/0gtweet/status/1457676633809330184
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-19
modified:2024-08-27
Tags:
  • -'attack.stealth'
  • -'attack.t1216'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\sigverif.exe'
  filter_main_werfault:
    Image:
      -'C:\Windows\System32\WerFault.exe'
      -'C:\Windows\SysWOW64\WerFault.exe'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: medium