This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - Empire PowerShell UAC Bypass
Original Source:
[Sigma source]
Title:
HackTool - Empire PowerShell UAC Bypass
Status:
stable
Description:
Detects some Empire PowerShell UAC bypass methods
References:
-https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/data/module_source/privesc/Invoke-EventVwrBypass.ps1#L64
-https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/data/module_source/privesc/Invoke-FodHelperBypass.ps1#L64
Author:
Ecco
Date:
2019-08-30
modified:
2023-02-21
Tags:
-'attack.privilege-escalation'
-'attack.t1548.002'
-'car.2019-04-001'
Logsource:
category: process_creation
product: windows
Detection:
selection:
CommandLine|contains
:
-' -NoP -NonI -w Hidden -c $x=$((gp HKCU:Software\Microsoft\Windows Update).Update)'
-' -NoP -NonI -c $x=$((gp HKCU:Software\Microsoft\Windows Update).Update);'
condition
:
selection
Falsepositives:
-Unknown
Level:
critical