Potential Meterpreter/CobaltStrike Activity

 Original Source: [Sigma source]
Title: Potential Meterpreter/CobaltStrike Activity
Status: test
Description:Detects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service starting
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-privilege-escalation-in-windows-environment
  -https://blog.cobaltstrike.com/2014/04/02/what-happens-when-i-type-getsystem/
Author: Teymur Kheirkhabarov, Ecco, Florian Roth
Date: 2019-10-26
modified:2023-02-05
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1134.001'
  • -'attack.t1134.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    ParentImage|endswith: '\services.exe'
  selection_technique_1:
    CommandLine|contains|all:
      -'/c'
      -'echo'
      -'\pipe\'

    CommandLine|contains:
      -'cmd'
      -'%COMSPEC%'

  selection_technique_2:
    CommandLine|contains|all:
      -'rundll32'
      -'.dll,a'
      -'/p:'

  filter_defender:
    CommandLine|contains: 'MpCmdRun'
  condition:selection_img and 1 of selection_technique_* and not 1 of filter_*
Falsepositives:
  -Commandlines containing components like cmd accidentally
  -Jobs and services started with cmd
Level: high