This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious AgentExecutor PowerShell Execution
Original Source:
[Sigma source]
Title:
Suspicious AgentExecutor PowerShell Execution
Status:
test
Description:
Detects execution of the AgentExecutor.exe binary. Which can be abused as a LOLBIN to execute powershell scripts with the ExecutionPolicy "Bypass" or any binary named "powershell.exe" located in the path provided by 6th positional argument
References:
-https://twitter.com/lefterispan/status/1286259016436514816
-https://lolbas-project.github.io/lolbas/OtherMSBinaries/Agentexecutor/
-https://learn.microsoft.com/en-us/mem/intune/apps/intune-management-extension
-https://twitter.com/jseerden/status/1247985304667066373/photo/1
Author:
Nasreddine Bencherchali (Nextron Systems), memory-shards
Date:
2022-12-24
modified:
2024-08-07
Tags:
-'attack.stealth'
-'attack.t1218'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\AgentExecutor.exe'
OriginalFileName
:
'AgentExecutor.exe'
selection_cli:
CommandLine|contains
:
-' -powershell'
-' -remediationScript'
filter_main_pwsh:
CommandLine|contains
:
-'C:\Windows\System32\WindowsPowerShell\v1.0\'
-'C:\Windows\SysWOW64\WindowsPowerShell\v1.0\'
filter_main_intune:
ParentImage|endswith
:
'\Microsoft.Management.Services.IntuneWindowsAgent.exe'
condition
:
all of selection_* and not 1 of filter_main_*
Falsepositives:
-Unknown
Level:
high