This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious DotNET CLR Usage Log Artifact
Original Source:
[Sigma source]
Title:
Suspicious DotNET CLR Usage Log Artifact
Status:
test
Description:
Detects the creation of Usage Log files by the CLR (clr.dll). These files are named after the executing process once the assembly is finished executing for the first time in the (user) session context.
References:
-https://bohops.com/2021/03/16/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion/
-https://github.com/olafhartong/sysmon-modular/blob/fa1ae53132403d262be2bbd7f17ceea7e15e8c78/11_file_create/include_dotnet.xml
-https://web.archive.org/web/20221026202428/https://gist.github.com/code-scrap/d7f152ffcdb3e0b02f7f394f5187f008
-https://web.archive.org/web/20230329154538/https://blog.menasec.net/2019/07/interesting-difr-traces-of-net-clr.html
Author:
frack113, omkar72, oscd.community, Wojciech Lesicki
Date:
2022-11-18
modified:
2023-02-23
Tags:
-'attack.stealth'
-'attack.t1218'
Logsource:
category: file_event
product: windows
definition: Requirements: UsageLogs folder must be monitored by the sysmon configuration
Detection:
selection:
TargetFilename|endswith
:
-'\UsageLogs\cmstp.exe.log'
-'\UsageLogs\cscript.exe.log'
-'\UsageLogs\mshta.exe.log'
-'\UsageLogs\msxsl.exe.log'
-'\UsageLogs\regsvr32.exe.log'
-'\UsageLogs\rundll32.exe.log'
-'\UsageLogs\svchost.exe.log'
-'\UsageLogs\wscript.exe.log'
-'\UsageLogs\wmic.exe.log'
filter_main_rundll32:
ParentImage|endswith
:
'\MsiExec.exe'
ParentCommandLine|contains
:
' -Embedding'
Image|endswith
:
'\rundll32.exe'
CommandLine|contains|all
:
-'Temp'
-'zzzzInvokeManagedCustomActionOutOfProc'
condition
:
selection and not 1 of filter_main_*
Falsepositives:
-Rundll32.exe with zzzzInvokeManagedCustomActionOutOfProc in command line and msiexec.exe as parent process - https://twitter.com/SBousseaden/status/1388064061087260675
Level:
high