Title:Potentially Suspicious Wuauclt Network Connection Status:test Description:Detects the use of the Windows Update Client binary (wuauclt.exe) to proxy execute code and making network connections.
One could easily make the DLL spawn a new process and inject to it to proxy the network connection and bypass this rule.
References: -https://dtm.uk/wuauclt/ Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) Date: 2020-10-12 modified:2024-03-12 Tags:
-'attack.stealth'
-'attack.t1218'
Logsource:
category: network_connection
product: windows
definition: Requirements: The CommandLine field enrichment is required in order for this rule to be used.
filter_main_cli_null: CommandLine:
'None' filter_main_cli_empty: CommandLine:
'' condition:selection and not 1 of filter_main_* Falsepositives:
-Unknown Level:medium