Non-privileged Usage of Reg or Powershell

 Original Source: [Sigma source]
Title: Non-privileged Usage of Reg or Powershell
Status: test
Description:Search for usage of reg or Powershell by non-privileged users to modify service configuration in registry
References:
  -https://image.slidesharecdn.com/kheirkhabarovoffzonefinal-181117201458/95/hunting-for-privilege-escalation-in-windows-environment-20-638.jpg
Author: Teymur Kheirkhabarov (idea), Ryan Plas (rule), oscd.community
Date: 2020-10-05
modified:2024-12-01
Tags:
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1112'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_cli:
    - CommandLine|contains|all:
      - 'reg '
      - 'add'
    - CommandLine|contains:
      - 'powershell'
      - 'set-itemproperty'
      - ' sp '
      - 'new-itemproperty'
  selection_data:
    IntegrityLevel:
      -'Medium'
      -'S-1-16-8192'

    CommandLine|contains|all:
      -'ControlSet'
      -'Services'

    CommandLine|contains:
      -'ImagePath'
      -'FailureCommand'
      -'ServiceDLL'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high