This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Scripting in a WMI Consumer
Original Source:
[Sigma source]
Title:
Suspicious Scripting in a WMI Consumer
Status:
test
Description:
Detects suspicious commands that are related to scripting/powershell in WMI Event Consumers
References:
-https://in.security/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/
-https://github.com/Neo23x0/signature-base/blob/615bf1f6bac3c1bdc417025c40c073e6c2771a76/yara/gen_susp_lnk_files.yar#L19
-https://github.com/RiccardoAncarani/LiquidSnake
Author:
Florian Roth (Nextron Systems), Jonhnathan Ribeiro
Date:
2019-04-15
modified:
2023-09-09
Tags:
-'attack.execution'
-'attack.t1059.005'
Logsource:
product: windows
category: wmi_event
Detection:
selection_destination:
- Destination|contains|all
:
- 'new-object'
- 'net.webclient'
- '.downloadstring'
- Destination|contains|all
:
- 'new-object'
- 'net.webclient'
- '.downloadfile'
- Destination|contains
:
- ' iex('
- ' -nop '
- ' -noprofile '
- ' -decode '
- ' -enc '
- 'WScript.Shell'
- 'System.Security.Cryptography.FromBase64Transform'
condition
:
selection_destination
Falsepositives:
-Legitimate administrative scripts
Level:
high