HackTool - SharpUp PrivEsc Tool Execution

 Original Source: [Sigma source]
Title: HackTool - SharpUp PrivEsc Tool Execution
Status: test
Description:Detects the use of SharpUp, a tool for local privilege escalation
References:
  -https://github.com/GhostPack/SharpUp
Author: Florian Roth (Nextron Systems)
Date: 2022-08-20
modified:2023-02-13
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.discovery'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1615'
  • -'attack.t1569.002'
  • -'attack.t1574.005'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
Image|endswith:'\SharpUp.exe' Description:'SharpUp'     - CommandLine|contains:
      - 'HijackablePaths'
      - 'UnquotedServicePath'
      - 'ProcessDLLHijack'
      - 'ModifiableServiceBinaries'
      - 'ModifiableScheduledTask'
      - 'DomainGPPPassword'
      - 'CachedGPPPassword'
  condition:selection
Falsepositives:
  -Unknown
Level: critical