This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - PPID Spoofing SelectMyParent Tool Execution
Original Source:
[Sigma source]
Title:
HackTool - PPID Spoofing SelectMyParent Tool Execution
Status:
test
Description:
Detects the use of parent process ID spoofing tools like Didier Stevens tool SelectMyParent
References:
-https://pentestlab.blog/2020/02/24/parent-pid-spoofing/
-https://www.picussecurity.com/resource/blog/how-to-detect-parent-pid-ppid-spoofing-attacks
-https://www.ired.team/offensive-security/defense-evasion/parent-process-id-ppid-spoofing
-https://www.virustotal.com/gui/search/filename%253A*spoof*%2520filename%253A*ppid*/files
Author:
Florian Roth (Nextron Systems)
Date:
2022-07-23
modified:
2024-11-23
Tags:
-'attack.privilege-escalation'
-'attack.stealth'
-'attack.t1134.004'
Logsource:
category: process_creation
product: windows
Detection:
selection:
Image|endswith
:
'\SelectMyParent.exe'
- CommandLine|contains
:
- 'PPID-spoof'
- 'ppid_spoof'
- 'spoof-ppid'
- 'spoof_ppid'
- 'ppidspoof'
- 'spoofppid'
- 'spoofedppid'
- ' -spawnto '
- OriginalFileName|contains
:
- 'PPID-spoof'
- 'ppid_spoof'
- 'spoof-ppid'
- 'spoof_ppid'
- 'ppidspoof'
- 'spoofppid'
- 'spoofedppid'
Description
:
'SelectMyParent'
- Hashes|contains
:
- 'IMPHASH=04D974875BD225F00902B4CAD9AF3FBC'
- 'IMPHASH=A782AF154C9E743DDF3F3EB2B8F3D16E'
- 'IMPHASH=89059503D7FBF470E68F7E63313DA3AD'
- 'IMPHASH=CA28337632625C8281AB8A130B3D6BAD'
condition
:
selection
Falsepositives:
-Unlikely
Level:
high