Operator Bloopers Cobalt Strike Commands

 Original Source: [Sigma source]
Title: Operator Bloopers Cobalt Strike Commands
Status: test
Description:Detects use of Cobalt Strike commands accidentally entered in the CMD shell
References:
  -https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/cobalt-4-5-user-guide.pdf
  -https://thedfirreport.com/2021/10/04/bazarloader-and-the-conti-leaks/
  -https://thedfirreport.com/2022/06/16/sans-ransomware-summit-2022-can-you-detect-this/
Author: _pete_0, TheDFIRReport
Date: 2022-05-06
modified:2023-01-30
Tags:
  • -'attack.execution'
  • -'attack.t1059.003'
  • -'stp.1u'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
OriginalFileName:'Cmd.Exe' Image|endswith:'\cmd.exe'   selection_cli:
    CommandLine|startswith:
      -'cmd '
      -'cmd.exe'
      -'c:\windows\system32\cmd.exe'

    CommandLine|contains:
      -'psinject'
      -'spawnas'
      -'make_token'
      -'remote-exec'
      -'rev2self'
      -'dcsync'
      -'logonpasswords'
      -'execute-assembly'
      -'getsystem'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high