AgentExecutor PowerShell Execution

 Original Source: [Sigma source]
Title: AgentExecutor PowerShell Execution
Status: test
Description:Detects execution of the AgentExecutor.exe binary. Which can be abused as a LOLBIN to execute powershell scripts with the ExecutionPolicy "Bypass" or any binary named "powershell.exe" located in the path provided by 6th positional argument
References:
  -https://twitter.com/lefterispan/status/1286259016436514816
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Agentexecutor/
  -https://learn.microsoft.com/en-us/mem/intune/apps/intune-management-extension
  -https://twitter.com/jseerden/status/1247985304667066373/photo/1
Author: Nasreddine Bencherchali (Nextron Systems), memory-shards
Date: 2022-12-24
modified:2024-08-07
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image:'\AgentExecutor.exe' OriginalFileName:'AgentExecutor.exe'   selection_cli:
    CommandLine|contains:
      -' -powershell'
      -' -remediationScript'

  filter_main_intune:
    ParentImage|endswith: '\Microsoft.Management.Services.IntuneWindowsAgent.exe'
  condition:all of selection_* and not 1 of filter_main_*
Falsepositives:
  -Legitimate use via Intune management. You exclude script paths and names to reduce FP rate
Level: medium