HackTool - SysmonEnte Execution

 Original Source: [Sigma source]
Title: HackTool - SysmonEnte Execution
Status: test
Description:Detects the use of SysmonEnte, a tool to attack the integrity of Sysmon
References:
  -https://codewhitesec.blogspot.com/2022/09/attacks-on-sysmon-revisited-sysmonente.html
  -https://github.com/codewhitesec/SysmonEnte/
  -https://github.com/codewhitesec/SysmonEnte/blob/fe267690fcc799fbda15398243615a30451d9099/screens/1.png
Author: Florian Roth (Nextron Systems)
Date: 2022-09-07
modified:2026-06-29
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685.001'
Logsource:
  • category: process_access
  • product: windows
Detection:
  selection_sysmon:
    TargetImage|contains:
      -':\Windows\Sysmon.exe'
      -':\Windows\Sysmon64.exe'
      -':\Windows\Sysmon64a.exe'

    GrantedAccess: '0x1400'
  selection_calltrace:
    CallTrace: 'Ente'
  filter_main_generic:
    SourceImage|contains:
      -':\Program Files (x86)\'
      -':\Program Files\'
      -':\Windows\System32\'
      -':\Windows\SysWOW64\'

  filter_main_msdefender:
    SourceImage|contains: ':\ProgramData\Microsoft\Windows Defender\Platform\'
    SourceImage|endswith: '\MsMpEng.exe'
  condition:( selection_sysmon and not 1 of filter_main_* ) or selection_calltrace
Falsepositives:
  -Unknown
Level: high