Potential Process Hollowing Activity

 Original Source: [Sigma source]
Title: Potential Process Hollowing Activity
Status: test
Description:Detects when a memory process image does not match the disk image, indicative of process hollowing.
References:
  -https://twitter.com/SecurePeacock/status/1486054048390332423?s=20
  -https://www.bleepingcomputer.com/news/microsoft/microsoft-sysmon-now-detects-malware-process-tampering-attempts/
Author: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Sittikorn S
Date: 2022-01-25
modified:2023-11-28
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1055.012'
Logsource:
  • product: windows
  • category: process_tampering
Detection:
  selection:
    Type: 'Image is replaced'
  filter_main_generic:
    Image|contains:
      -':\Program Files (x86)'
      -':\Program Files\'
      -':\Windows\System32\wbem\WMIADAP.exe'
      -':\Windows\SysWOW64\wbem\WMIADAP.exe'

  filter_optional_opera:
    Image|contains: '\AppData\Local\Programs\Opera\'
    Image|endswith: '\opera.exe'
  filter_optional_edge:
    Image|endswith: '\WindowsApps\MicrosoftEdge.exe'
  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: medium