Potential Binary Proxy Execution Via Cdb.EXE

 Original Source: [Sigma source]
Title: Potential Binary Proxy Execution Via Cdb.EXE
Status: test
Description:Detects usage of "cdb.exe" to launch arbitrary processes or commands from a debugger script file
References:
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/
  -https://web.archive.org/web/20170715043507/http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html
  -https://twitter.com/nas_bench/status/1534957360032120833
Author: Beyu Denis, oscd.community, Nasreddine Bencherchali (Nextron Systems)
Date: 2019-10-26
modified:2024-04-22
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1106'
  • -'attack.t1218'
  • -'attack.t1127'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\cdb.exe' OriginalFileName:'CDB.Exe'   selection_cli:
    CommandLine|contains:
      -' -c '
      -' -cf '

  condition:all of selection*
Falsepositives:
  -Legitimate use of debugging tools
Level: medium