HackTool - Potential CobaltStrike Process Injection

 Original Source: [Sigma source]
Title: HackTool - Potential CobaltStrike Process Injection
Status: test
Description:Detects a potential remote threat creation with certain characteristics which are typical for Cobalt Strike beacons
References:
  -https://medium.com/@olafhartong/cobalt-strike-remote-threads-detection-206372d11d0f
  -https://blog.cobaltstrike.com/2018/04/09/cobalt-strike-3-11-the-snake-that-eats-its-tail/
Author: Olaf Hartong, Florian Roth (Nextron Systems), Aleksey Potapov, oscd.community
Date: 2018-11-30
modified:2023-05-05
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1055.001'
Logsource:
  • product: windows
  • category: create_remote_thread
Detection:
  selection:
    StartAddress|endswith:
      -'0B80'
      -'0C7C'
      -'0C88'

  condition:selection
Falsepositives:
  -Unknown
Level: high