HackTool - Powerup Write Hijack DLL

 Original Source: [Sigma source]
Title: HackTool - Powerup Write Hijack DLL
Status: test
Description:Powerup tool's Write Hijack DLL exploits DLL hijacking for privilege escalation. In it's default mode, it builds a self deleting .bat file which executes malicious command. The detection rule relies on creation of the malicious bat file (debug.bat by default).
References:
  -https://powersploit.readthedocs.io/en/latest/Privesc/Write-HijackDll/
Author: Subhash Popuri (@pbssubhash)
Date: 2021-08-21
modified:2024-06-27
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • category: file_event
  • product: windows
Detection:
  selection:
    Image|endswith:
      -'\powershell.exe'
      -'\pwsh.exe'

    TargetFilename|endswith: '.bat'
  condition:selection
Falsepositives:
  -Any powershell script that creates bat files
Level: high