Remote Thread Created In Shell Application

 Original Source: [Sigma source]
Title: Remote Thread Created In Shell Application
Status: test
Description:Detects remote thread creation in command shell applications, such as "Cmd.EXE" and "PowerShell.EXE". It is a common technique used by malware, such as IcedID, to inject malicious code and execute it within legitimate processes.
References:
  -https://research.splunk.com/endpoint/10399c1e-f51e-11eb-b920-acde48001122/
  -https://www.binarydefense.com/resources/blog/icedid-gziploader-analysis/
Author: Splunk Research Team
Date: 2024-07-29
modified:None
Tags:
  • -'attack.defense-evasion'
  • -'attack.t1055'
Logsource:
  • product: windows
  • category: create_remote_thread
Detection:
  selection:
    TargetImage|endswith:
      -'\cmd.exe'
      -'\powershell.exe'
      -'\pwsh.exe'

  condition:selection
Falsepositives:
  -Unknown
Level: medium