Suspicious DLL Loaded via CertOC.EXE

 Original Source: [Sigma source]
Title: Suspicious DLL Loaded via CertOC.EXE
Status: test
Description:Detects when a user installs certificates by using CertOC.exe to load the target DLL file.
References:
  -https://twitter.com/sblmsrsn/status/1445758411803480072?s=20
  -https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-fe98e74189873d6df72a15df2eaa0315c59ba9cdaca93ecd68afc4ea09194ef2
  -https://lolbas-project.github.io/lolbas/Binaries/Certoc/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-02-15
modified:2024-03-05
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\certoc.exe' OriginalFileName:'CertOC.exe'   selection_cli:
    CommandLine|contains|windash: ' -LoadDLL '
  selection_paths:
    CommandLine|contains:
      -'\Appdata\Local\Temp\'
      -'\Desktop\'
      -'\Downloads\'
      -'\Users\Public\'
      -'C:\Windows\Tasks\'
      -'C:\Windows\Temp\'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high