Access To Potentially Sensitive Sysvol Files By Uncommon Applications

 Original Source: [Sigma source]
Title: Access To Potentially Sensitive Sysvol Files By Uncommon Applications
Status: test
Description:Detects file access requests to potentially sensitive files hosted on the Windows Sysvol share.
References:
  -https://github.com/vletoux/pingcastle
Author: frack113
Date: 2023-12-21
modified:2024-07-29
Tags:
  • -'attack.credential-access'
  • -'attack.t1552.006'
Logsource:
  • category: file_access
  • product: windows
  • definition: Requirements: Microsoft-Windows-Kernel-File ETW provider
Detection:
  selection:
    FileName|startswith: '\\'
    FileName|contains|all:
      -'\sysvol\'
      -'\Policies\'

    FileName|endswith:
      -'audit.csv'
      -'Files.xml'
      -'GptTmpl.inf'
      -'groups.xml'
      -'Registry.pol'
      -'Registry.xml'
      -'scheduledtasks.xml'
      -'scripts.ini'
      -'services.xml'

  filter_main_generic:
    Image|startswith:
      -'C:\Program Files (x86)\'
      -'C:\Program Files\'
      -'C:\Windows\system32\'
      -'C:\Windows\SysWOW64\'

  filter_main_explorer:
    Image: 'C:\Windows\explorer.exe'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: medium