Potentially Suspicious Execution From Parent Process In Public Folder

 Original Source: [Sigma source]
Title: Potentially Suspicious Execution From Parent Process In Public Folder
Status: test
Description:Detects a potentially suspicious execution of a parent process located in the "\Users\Public" folder executing a child process containing references to shell or scripting binaries and commandlines.
References:
  -https://redcanary.com/blog/blackbyte-ransomware/
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2022-02-25
modified:2024-07-12
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1564'
  • -'attack.t1059'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_parent:
    ParentImage|contains: ':\Users\Public\'
  selection_child:
    - Image|endswith:
      - '\bitsadmin.exe'
      - '\certutil.exe'
      - '\cmd.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\regsvr32.exe'
      - '\rundll32.exe'
      - '\wscript.exe'
    - CommandLine|contains:
      - 'bitsadmin'
      - 'certutil'
      - 'cscript'
      - 'mshta'
      - 'powershell'
      - 'regsvr32'
      - 'rundll32'
      - 'wscript'
  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high