Name:Windows LOLBAS Executed Outside Expected Path id:326fdf44-b90c-4d2e-adca-1fd140b10536 version:10 date:None author:Steven Dick status:production type:Anomaly Description:The following analytic identifies a LOLBAS process being executed outside of it's expected location.
Processes being executed outside of expected locations may be an indicator that an adversary is attempting to evade defenses or execute malicious code.
The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.
Data_source:
-Sysmon EventID 1
-Windows Event Log Security 4688
search:| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where
NOT Processes.process_path IN ( "*\\PROGRA~*", "*\\Program Files \(x86\)\\", "*\\Program Files\\", "*:\\Windows\\System32\\*", "*:\\Windows\\SysWOW64\\*", "*:\\Windows\\WinSxS\\*" )
|`drop_dm_object_name(Processes)` | lookup lolbas_file_path lolbas_file_name as process_name OUTPUT description as desc | lookup lolbas_file_path lolbas_file_name as process_name lolbas_file_path as process_path OUTPUT description as is_lolbas_path | search desc!="false" AND is_lolbas_path="false" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_lolbas_executed_outside_expected_path_filter`
how_to_implement:To implement this search, you must ingest logs that contain the process name and process path, such as with Sysmon EID 1. known_false_positives:Vendors, third party software or update processes may use versions of the binaries listed in the lookup table from non-standard paths.
It is recommended to tune this analytic to exclude any known legitimate software or paths in your environment
References: -https://attack.mitre.org/techniques/T1036/ -https://attack.mitre.org/techniques/T1036/005/ drilldown_searches: name:'View the detection results for - "$user$" and "$dest$"' search:'%original_detection_search% | search user = "$user$" dest = "$dest$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$user$" and "$dest$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['Living Off The Land', 'Masquerading - Rename System Utilities', 'Windows Defense Evasion Tactics']