Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS

 Original Source: [Sigma source]
Title: Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS
Status: test
Description:Detects execution of the built-in script located in "C:\Windows\System32\gatherNetworkInfo.vbs". Which can be used to gather information about the target machine
References:
  -https://posts.slayerlabs.com/living-off-the-land/#gathernetworkinfovbs
  -https://www.mandiant.com/resources/blog/trojanized-windows-installers-ukrainian-government
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-02-08
modified:None
Tags:
  • -'attack.discovery'
  • -'attack.execution'
  • -'attack.t1615'
  • -'attack.t1059.005'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains: 'gatherNetworkInfo.vbs'
  filter:
    Image|endswith:
      -'\cscript.exe'
      -'\wscript.exe'

  condition:selection and not filter
Falsepositives:
  -Unknown
Level: high