This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Data Export From MSSQL Table Via BCP.EXE
Original Source:
[Sigma source]
Title:
Data Export From MSSQL Table Via BCP.EXE
Status:
test
Description:
Detects the execution of the BCP utility in order to export data from the database. Attackers were seen saving their malware to a database column or table and then later extracting it via "bcp.exe" into a file.
References:
-https://docs.microsoft.com/en-us/sql/tools/bcp-utility
-https://asec.ahnlab.com/en/61000/
-https://asec.ahnlab.com/en/78944/
-https://www.huntress.com/blog/attacking-mssql-servers
-https://www.huntress.com/blog/attacking-mssql-servers-pt-ii
-https://news.sophos.com/en-us/2024/08/07/sophos-mdr-hunt-tracks-mimic-ransomware-campaign-against-organizations-in-india/
-https://research.nccgroup.com/2018/03/10/apt15-is-alive-and-strong-an-analysis-of-royalcli-and-royaldns/
Author:
Omar Khaled (@beacon_exe), MahirAli Khan (in/mahiralikhan), Nasreddine Bencherchali (Nextron Systems)
Date:
2024-08-20
modified:
None
Tags:
-'attack.execution'
-'attack.exfiltration'
-'attack.t1048'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\bcp.exe'
OriginalFileName
:
'BCP.exe'
selection_cli:
CommandLine|contains
:
-' out '
-' queryout '
condition
:
all of selection_*
Falsepositives:
-Legitimate data export operations.
Level:
medium