This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Dllhost.EXE Execution Anomaly
Original Source:
[Sigma source]
Title:
Dllhost.EXE Execution Anomaly
Status:
test
Description:
Detects a "dllhost" process spawning with no commandline arguments which is very rare to happen and could indicate process injection activity or malware mimicking similar system processes.
References:
-https://redcanary.com/blog/child-processes/
-https://nasbench.medium.com/what-is-the-dllhost-exe-process-actually-running-ef9fe4c19c08
-https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/goofy-guineapig/NCSC-MAR-Goofy-Guineapig.pdf
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-06-27
modified:
2023-05-15
Tags:
-'attack.privilege-escalation'
-'attack.stealth'
-'attack.t1055'
Logsource:
category: process_creation
product: windows
Detection:
selection:
Image|endswith
:
'\dllhost.exe'
CommandLine
:
-'dllhost.exe'
-'dllhost'
filter_main_null:
CommandLine
:
'None'
condition
:
selection and not 1 of filter_main_*
Falsepositives:
-Unlikely
Level:
high