Uncommon Child Process Of AddinUtil.EXE

 Original Source: [Sigma source]
Title: Uncommon Child Process Of AddinUtil.EXE
Status: test
Description:Detects uncommon child processes of the Add-In deployment cache updating utility (AddInutil.exe) which could be a sign of potential abuse of the binary to proxy execution via a custom Addins.Store payload.
References:
  -https://www.blue-prints.blog/content/blog/posts/lolbin/addinutil-lolbas.html
Author: Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri)
Date: 2023-09-18
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\addinutil.exe'
  filter_main_werfault:
    Image|endswith:
      -':\Windows\System32\conhost.exe'
      -':\Windows\System32\werfault.exe'
      -':\Windows\SysWOW64\werfault.exe'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: medium