Title:
Potential Remote PowerShell Session Initiated
Status:
test
Description:Detects a process that initiated a network connection over ports 5985 or 5986 from a non-network service account.
This could potentially indicates a remote PowerShell connection.
References:
-https://threathunterplaybook.com/hunts/windows/190511-RemotePwshExecution/notebook.html
Author: Roberto Rodriguez @Cyb3rWard0g
Date: 2019-09-12
modified:2024-02-02
Tags:
- -'attack.execution'
- -'attack.t1059.001'
- -'attack.lateral-movement'
- -'attack.t1021.006'
Logsource:
- category: network_connection
- product: windows
Detection:
selection:
DestinationPort:
-'5985'
-'5986'
Initiated:
'true'
SourceIsIpv6:
'false'
filter_main_service_users:
- User|contains:
- 'NETWORK SERVICE'
- 'NETZWERKDIENST'
- 'SERVICIO DE RED'
- 'SERVIZIO DI RETE'
- User|contains|all:
- 'SERVICE R'
- 'SEAU'
filter_main_localhost:
SourceIp:
-'::1'
-'127.0.0.1'
DestinationIp:
-'::1'
-'127.0.0.1'
filter_optional_avast:
Image:
-'C:\Program Files\Avast Software\Avast\AvastSvc.exe'
-'C:\Program Files (x86)\Avast Software\Avast\AvastSvc.exe'
condition:
selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
-Legitimate usage of remote PowerShell, e.g. remote administration and monitoring.
-Network Service user name of a not-covered localization
Level:
high