This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Insensitive Subfolder Search Via Findstr.EXE
Original Source:
[Sigma source]
Title:
Insensitive Subfolder Search Via Findstr.EXE
Status:
test
Description:
Detects execution of findstr with the "s" and "i" flags for a "subfolder" and "insensitive" search respectively. Attackers sometimes leverage this built-in utility to search the system for interesting files or filter through results of commands.
References:
-https://lolbas-project.github.io/lolbas/Binaries/Findstr/
-https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/
-https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f
Author:
Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems)
Date:
2020-10-05
modified:
2024-03-05
Tags:
-'attack.credential-access'
-'attack.command-and-control'
-'attack.stealth'
-'attack.t1218'
-'attack.t1564.004'
-'attack.t1552.001'
-'attack.t1105'
Logsource:
category: process_creation
product: windows
Detection:
selection_findstr:
CommandLine|contains
:
'findstr'
Image|endswith
:
'findstr.exe'
OriginalFileName
:
'FINDSTR.EXE'
selection_cli_search_subfolder:
CommandLine|contains|windash
:
' -s '
selection_cli_search_insensitive:
CommandLine|contains|windash
:
' -i '
condition
:
selection_findstr and all of selection_cli_search_*
Falsepositives:
-Administrative or software activity
Level:
low