Remote Thread Creation Via PowerShell In Uncommon Target

 Original Source: [Sigma source]
Title: Remote Thread Creation Via PowerShell In Uncommon Target
Status: test
Description:Detects the creation of a remote thread from a Powershell process in an uncommon target process
References:
  -https://www.fireeye.com/blog/threat-research/2018/06/bring-your-own-land-novel-red-teaming-technique.html
Author: Florian Roth (Nextron Systems)
Date: 2018-06-25
modified:2023-11-10
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1218.011'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: create_remote_thread
Detection:
  selection:
    SourceImage|endswith:
      -'\powershell.exe'
      -'\pwsh.exe'

    TargetImage|endswith:
      -'\rundll32.exe'
      -'\regsvr32.exe'

  condition:selection
Falsepositives:
  -Unknown
Level: medium