Uncommon Userinit Child Process

 Original Source: [Sigma source]
Title: Uncommon Userinit Child Process
Status: test
Description:Detects uncommon "userinit.exe" child processes, which could be a sign of uncommon shells or login scripts used for persistence.
References:
  -https://cocomelonc.github.io/persistence/2022/12/09/malware-pers-20.html
  -https://learn.microsoft.com/en-us/windows-server/administration/server-core/server-core-sconfig#powershell-is-the-default-shell-on-server-core
Author: Tom Ueltschi (@c_APT_ure), Tim Shelton
Date: 2019-01-12
modified:2023-11-14
Tags:
  • -'attack.privilege-escalation'
  • -'attack.t1037.001'
  • -'attack.persistence'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\userinit.exe'
  filter_main_explorer:
    Image|endswith: ':\WINDOWS\explorer.exe'
  filter_optional_logonscripts:
    CommandLine|contains:
      -'netlogon.bat'
      -'UsrLogon.cmd'

  filter_optional_windows_core:
    CommandLine: 'PowerShell.exe'
  filter_optional_proquota:
    Image|endswith:
      -':\Windows\System32\proquota.exe'
      -':\Windows\SysWOW64\proquota.exe'

  filter_optional_citrix:
    Image|endswith:
      -':\Program Files (x86)\Citrix\HDX\bin\cmstart.exe'
      -':\Program Files (x86)\Citrix\HDX\bin\icast.exe'
      -':\Program Files (x86)\Citrix\System32\icast.exe'
      -':\Program Files\Citrix\HDX\bin\cmstart.exe'
      -':\Program Files\Citrix\HDX\bin\icast.exe'
      -':\Program Files\Citrix\System32\icast.exe'

  filter_optional_image_null:
    Image: 'None'
  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Legitimate logon scripts or custom shells may trigger false positives. Apply additional filters accordingly.
Level: high