Title:
MITRE BZAR Indicators for Persistence
Status:
test
Description:Windows DCE-RPC functions which indicate a persistence techniques on the remote system. All credit for the Zeek mapping of the suspicious endpoint/operation field goes to MITRE.
References:
-https://github.com/mitre-attack/bzar#indicators-for-attck-persistence
Author: @neu5ron, SOC Prime
Date: 2020-03-19
modified:2021-11-27
Tags:
- -'attack.privilege-escalation'
- -'attack.persistence'
- -'attack.t1547.004'
Logsource:
- product: zeek
- service: dce_rpc
Detection:
op1:
endpoint:
'spoolss'
operation:
'RpcAddMonitor'
op2:
endpoint:
'spoolss'
operation:
'RpcAddPrintProcessor'
op3:
endpoint:
'IRemoteWinspool'
operation:
'RpcAsyncAddMonitor'
op4:
endpoint:
'IRemoteWinspool'
operation:
'RpcAsyncAddPrintProcessor'
op5:
endpoint:
'ISecLogon'
operation:
'SeclCreateProcessWithLogonW'
op6:
endpoint:
'ISecLogon'
operation:
'SeclCreateProcessWithLogonExW'
condition:
1 of op*
Falsepositives:
-Windows administrator tasks or troubleshooting
-Windows management scripts or software
Level:
medium