HackTool - DInjector PowerShell Cradle Execution

 Original Source: [Sigma source]
Title: HackTool - DInjector PowerShell Cradle Execution
Status: test
Description:Detects the use of the Dinject PowerShell cradle based on the specific flags
References:
  -https://web.archive.org/web/20211001064856/https://github.com/snovvcrash/DInjector
Author: Florian Roth (Nextron Systems)
Date: 2021-12-07
modified:2023-02-04
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1055'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -' /am51'
      -' /password'

  condition:selection
Falsepositives:
  -Unlikely
Level: critical