Sticky Key Like Backdoor Execution

 Original Source: [Sigma source]
Title: Sticky Key Like Backdoor Execution
Status: test
Description:Detects the usage and installation of a backdoor that uses an option to register a malicious debugger for built-in tools that are accessible in the login screen
References:
  -https://learn.microsoft.com/en-us/archive/blogs/jonathantrull/detecting-sticky-key-backdoors
Author: Florian Roth (Nextron Systems), @twjackomo, Jonhnathan Ribeiro, oscd.community
Date: 2018-03-15
modified:2023-03-07
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1546.008'
  • -'car.2014-11-003'
  • -'car.2014-11-008'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\winlogon.exe'
    Image|endswith:
      -'\cmd.exe'
      -'\cscript.exe'
      -'\mshta.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\regsvr32.exe'
      -'\rundll32.exe'
      -'\wscript.exe'
      -'\wt.exe'

    CommandLine|contains:
      -'sethc.exe'
      -'utilman.exe'
      -'osk.exe'
      -'Magnify.exe'
      -'Narrator.exe'
      -'DisplaySwitch.exe'

  condition:selection
Falsepositives:
  -Unlikely
Level: critical