This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - Powerup Write Hijack DLL
Original Source:
[Sigma source]
Title:
HackTool - Powerup Write Hijack DLL
Status:
test
Description:
Powerup tool's Write Hijack DLL exploits DLL hijacking for privilege escalation. In it's default mode, it builds a self deleting .bat file which executes malicious command. The detection rule relies on creation of the malicious bat file (debug.bat by default).
References:
-https://powersploit.readthedocs.io/en/latest/Privesc/Write-HijackDll/
Author:
Subhash Popuri (@pbssubhash)
Date:
2021-08-21
modified:
2024-06-27
Tags:
-'attack.persistence'
-'attack.privilege-escalation'
-'attack.execution'
-'attack.stealth'
-'attack.t1574.001'
Logsource:
category: file_event
product: windows
Detection:
selection:
Image|endswith
:
-'\powershell.exe'
-'\pwsh.exe'
TargetFilename|endswith
:
'.bat'
condition
:
selection
Falsepositives:
-Any powershell script that creates bat files
Level:
high