Title:
MITRE BZAR Indicators for Execution
Status:
test
Description:Windows DCE-RPC functions which indicate an execution techniques on the remote system. All credit for the Zeek mapping of the suspicious endpoint/operation field goes to MITRE
References:
-https://github.com/mitre-attack/bzar#indicators-for-attck-execution
Author: @neu5ron, SOC Prime
Date: 2020-03-19
modified:2021-11-27
Tags:
- -'attack.privilege-escalation'
- -'attack.persistence'
- -'attack.execution'
- -'attack.t1047'
- -'attack.t1053.002'
- -'attack.t1569.002'
Logsource:
- product: zeek
- service: dce_rpc
Detection:
op1:
endpoint:
'JobAdd'
operation:
'atsvc'
op2:
endpoint:
'ITaskSchedulerService'
operation:
'SchRpcEnableTask'
op3:
endpoint:
'ITaskSchedulerService'
operation:
'SchRpcRegisterTask'
op4:
endpoint:
'ITaskSchedulerService'
operation:
'SchRpcRun'
op5:
endpoint:
'IWbemServices'
operation:
'ExecMethod'
op6:
endpoint:
'IWbemServices'
operation:
'ExecMethodAsync'
op7:
endpoint:
'svcctl'
operation:
'CreateServiceA'
op8:
endpoint:
'svcctl'
operation:
'CreateServiceW'
op9:
endpoint:
'svcctl'
operation:
'StartServiceA'
op10:
endpoint:
'svcctl'
operation:
'StartServiceW'
condition:
1 of op*
Falsepositives:
-Windows administrator tasks or troubleshooting
-Windows management scripts or software
Level:
medium