This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Windows Shell/Scripting Processes Spawning Suspicious Programs
Original Source:
[Sigma source]
Title:
Windows Shell/Scripting Processes Spawning Suspicious Programs
Status:
test
Description:
Detects suspicious child processes of a Windows shell and scripting processes such as wscript, rundll32, powershell, mshta...etc.
References:
-https://mgreen27.github.io/posts/2018/04/02/DownloadCradle.html
Author:
Florian Roth (Nextron Systems), Tim Shelton
Date:
2018-04-06
modified:
2023-05-23
Tags:
-'attack.execution'
-'attack.stealth'
-'attack.t1059.005'
-'attack.t1059.001'
-'attack.t1218'
Logsource:
category: process_creation
product: windows
Detection:
selection:
ParentImage|endswith
:
-'\mshta.exe'
-'\powershell.exe'
-'\pwsh.exe'
-'\rundll32.exe'
-'\cscript.exe'
-'\wscript.exe'
-'\wmiprvse.exe'
-'\regsvr32.exe'
Image|endswith
:
-'\schtasks.exe'
-'\nslookup.exe'
-'\certutil.exe'
-'\bitsadmin.exe'
-'\mshta.exe'
filter_ccmcache:
CurrentDirectory|contains
:
'\ccmcache\'
filter_amazon:
ParentCommandLine|contains
:
-'\Program Files\Amazon\WorkSpacesConfig\Scripts\setup-scheduledtask.ps1'
-'\Program Files\Amazon\WorkSpacesConfig\Scripts\set-selfhealing.ps1'
-'\Program Files\Amazon\WorkSpacesConfig\Scripts\check-workspacehealth.ps1'
-'\nessus_'
filter_nessus:
CommandLine|contains
:
'\nessus_'
filter_sccm_install:
ParentImage|endswith
:
'\mshta.exe'
Image|endswith
:
'\mshta.exe'
ParentCommandLine|contains|all
:
-'C:\MEM_Configmgr_'
-'\splash.hta'
-'{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}'
CommandLine|contains|all
:
-'C:\MEM_Configmgr_'
-'\SMSSETUP\BIN\'
-'\autorun.hta'
-'{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}'
condition
:
selection and not 1 of filter_*
Falsepositives:
-Administrative scripts
-Microsoft SCCM
Level:
high