Title:Uncommon Child Process Of Conhost.EXE Status:test Description:Detects uncommon "conhost" child processes. This could be a sign of "conhost" usage as a LOLBIN or potential process injection activity. References: -http://www.hexacorn.com/blog/2020/05/25/how-to-con-your-host/ Author: omkar72 Date: 2020-10-25 modified:2023-12-11 Tags:
-'attack.stealth'
-'attack.t1202'
Logsource:
category: process_creation
product: windows
Detection: selection: ParentImage|endswith:
'\conhost.exe' filter_main_conhost: Image|endswith:
':\Windows\System32\conhost.exe' filter_main_null: Image:
'None' filter_main_empty: Image:
'' filter_optional_provider: Provider_Name:
'SystemTraceProvider-Process' condition:selection and not 1 of filter_main_* and not 1 of filter_optional_* Falsepositives:
-Unknown Level:medium