Title:
Suspicious Use of CSharp Interactive Console
Status:
test
Description:Detects the execution of CSharp interactive console by PowerShell
References:
-https://redcanary.com/blog/detecting-attacks-leveraging-the-net-framework/
Author: Michael R. (@nahamike01)
Date: 2020-03-08
modified:2022-07-14
Tags:
- -'attack.execution'
- -'attack.stealth'
- -'attack.t1127'
Logsource:
- category: process_creation
- product: windows
Detection:
selection:
Image|endswith:
'\csi.exe'
ParentImage|endswith:
-'\powershell.exe'
-'\pwsh.exe'
-'\powershell_ise.exe'
OriginalFileName:
'csi.exe'
condition:
selection
Falsepositives:
-Possible depending on environment. Pair with other factors such as net connections, command-line args, etc.
Level:
high