Title:
Potential Meterpreter/CobaltStrike Activity
Status:
test
Description:Detects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service starting
References:
-https://speakerdeck.com/heirhabarov/hunting-for-privilege-escalation-in-windows-environment
-https://blog.cobaltstrike.com/2014/04/02/what-happens-when-i-type-getsystem/
Author: Teymur Kheirkhabarov, Ecco, Florian Roth
Date: 2019-10-26
modified:2023-02-05
Tags:
- -'attack.privilege-escalation'
- -'attack.stealth'
- -'attack.t1134.001'
- -'attack.t1134.002'
Logsource:
- category: process_creation
- product: windows
Detection:
selection_img:
ParentImage|endswith:
'\services.exe'
selection_technique_1:
CommandLine|contains|all:
-'/c'
-'echo'
-'\pipe\'
CommandLine|contains:
-'cmd'
-'%COMSPEC%'
selection_technique_2:
CommandLine|contains|all:
-'rundll32'
-'.dll,a'
-'/p:'
filter_defender:
CommandLine|contains:
'MpCmdRun'
condition:
selection_img and 1 of selection_technique_* and not 1 of filter_*
Falsepositives:
-Commandlines containing components like cmd accidentally
-Jobs and services started with cmd
Level:
high