Title:
Security Software Discovery Via Powershell Script
Status:
test
Description:Detects calls to "get-process" where the output is piped to a "where-object" filter to search for security solution processes.
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as firewall rules and anti-virus
References:
-https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1518.001/T1518.001.md#atomic-test-2---security-software-discovery---powershell
Author: frack113, Anish Bogati, Nasreddine Bencherchali (Nextron Systems)
Date: 2021-12-16
modified:2023-10-24
Tags:
- -'attack.discovery'
- -'attack.t1518.001'
Logsource:
- product: windows
- category: ps_script
- definition: Requirements: Script Block Logging must be enabled
Detection:
selection_cmdlet:
ScriptBlockText|contains:
-'get-process | \?'
-'get-process | where'
-'gps | \?'
-'gps | where'
selection_field:
ScriptBlockText|contains:
-'Company -like'
-'Description -like'
-'Name -like'
-'Path -like'
-'Product -like'
selection_keywords:
ScriptBlockText|contains:
-'\*avira\*'
-'\*carbonblack\*'
-'\*cylance\*'
-'\*defender\*'
-'\*kaspersky\*'
-'\*malware\*'
-'\*sentinel\*'
-'\*symantec\*'
-'\*virus\*'
condition:
all of selection_*
Falsepositives:
-False positives might occur due to the nature of the ScriptBlock being ingested as a big blob. Initial tuning is required.
-As the "selection_cmdlet" is common in scripts the matching engine might slow down the search. Change into regex or a more accurate string to avoid heavy resource consumption if experienced
Level:
medium