Suspect Svchost Activity

 Original Source: [Sigma source]
Title: Suspect Svchost Activity
Status: test
Description:It is extremely abnormal for svchost.exe to spawn without any CLI arguments and is normally observed when a malicious process spawns the process and injects code into the process memory space.
References:
  -https://web.archive.org/web/20180718061628/https://securitybytes.io/blue-team-fundamentals-part-two-windows-processes-759fe15965e2
Author: David Burkett, @signalblur
Date: 2019-12-28
modified:2022-06-27
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1055'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|endswith: 'svchost.exe'
    Image|endswith: '\svchost.exe'
  filter:
    - ParentImage|endswith:
      - '\rpcnet.exe'
      - '\rpcnetp.exe'
CommandLine:'None'   condition:selection and not filter
Falsepositives:
  -Rpcnet.exe / rpcnetp.exe which is a lojack style software. https://www.blackhat.com/docs/us-14/materials/us-14-Kamlyuk-Kamluk-Computrace-Backdoor-Revisited.pdf
Level: high