Suspicious DotNET CLR Usage Log Artifact

 Original Source: [Sigma source]
Title: Suspicious DotNET CLR Usage Log Artifact
Status: test
Description:Detects the creation of Usage Log files by the CLR (clr.dll). These files are named after the executing process once the assembly is finished executing for the first time in the (user) session context.
References:
  -https://bohops.com/2021/03/16/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion/
  -https://github.com/olafhartong/sysmon-modular/blob/fa1ae53132403d262be2bbd7f17ceea7e15e8c78/11_file_create/include_dotnet.xml
  -https://web.archive.org/web/20221026202428/https://gist.github.com/code-scrap/d7f152ffcdb3e0b02f7f394f5187f008
  -https://web.archive.org/web/20230329154538/https://blog.menasec.net/2019/07/interesting-difr-traces-of-net-clr.html
Author: frack113, omkar72, oscd.community, Wojciech Lesicki
Date: 2022-11-18
modified:2023-02-23
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: file_event
  • product: windows
  • definition: Requirements: UsageLogs folder must be monitored by the sysmon configuration
Detection:
  selection:
    TargetFilename|endswith:
      -'\UsageLogs\cmstp.exe.log'
      -'\UsageLogs\cscript.exe.log'
      -'\UsageLogs\mshta.exe.log'
      -'\UsageLogs\msxsl.exe.log'
      -'\UsageLogs\regsvr32.exe.log'
      -'\UsageLogs\rundll32.exe.log'
      -'\UsageLogs\svchost.exe.log'
      -'\UsageLogs\wscript.exe.log'
      -'\UsageLogs\wmic.exe.log'

  filter_main_rundll32:
    ParentImage|endswith: '\MsiExec.exe'
    ParentCommandLine|contains: ' -Embedding'
    Image|endswith: '\rundll32.exe'
    CommandLine|contains|all:
      -'Temp'
      -'zzzzInvokeManagedCustomActionOutOfProc'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Rundll32.exe with zzzzInvokeManagedCustomActionOutOfProc in command line and msiexec.exe as parent process - https://twitter.com/SBousseaden/status/1388064061087260675
Level: high