Suspicious Windows Update Agent Empty Cmdline

 Original Source: [Sigma source]
Title: Suspicious Windows Update Agent Empty Cmdline
Status: test
Description:Detects suspicious Windows Update Agent activity in which a wuauclt.exe process command line doesn't contain any command line flags
References:
  -https://redcanary.com/blog/blackbyte-ransomware/
Author: Florian Roth (Nextron Systems)
Date: 2022-02-26
modified:2023-11-11
Tags:
  • -'attack.stealth'
  • -'attack.t1036'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\Wuauclt.exe' OriginalFileName:'Wuauclt.exe'   selection_cli:
    CommandLine|endswith:
      -'Wuauclt'
      -'Wuauclt.exe'

  condition:all of selection*
Falsepositives:
  -Unknown
Level: high