HackTool - SharpWSUS/WSUSpendu Execution

 Original Source: [Sigma source]
Title: HackTool - SharpWSUS/WSUSpendu Execution
Status: test
Description:Detects the execution of SharpWSUS or WSUSpendu, utilities that allow for lateral movement through WSUS. Windows Server Update Services (WSUS) is a critical component of Windows systems and is frequently configured in a way that allows an attacker to circumvent internal networking limitations.
References:
  -https://labs.nettitude.com/blog/introducing-sharpwsus/
  -https://github.com/nettitude/SharpWSUS
  -https://web.archive.org/web/20210512154016/https://github.com/AlsidOfficial/WSUSpendu/blob/master/WSUSpendu.ps1
Author: @Kostastsale, Nasreddine Bencherchali (Nextron Systems)
Date: 2022-10-07
modified:2024-08-23
Tags:
  • -'attack.execution'
  • -'attack.lateral-movement'
  • -'attack.t1210'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_wsuspendu_inject:
    CommandLine|contains: ' -Inject '
  selection_wsuspendu_payload:
    CommandLine|contains:
      -' -PayloadArgs '
      -' -PayloadFile '

  selection_sharpwsus_commands:
    CommandLine|contains:
      -' approve '
      -' create '
      -' check '
      -' delete '

  selection_sharpwsus_flags:
    CommandLine|contains:
      -' /payload:'
      -' /payload='
      -' /updateid:'
      -' /updateid='

  condition:all of selection_wsuspendu_* or all of selection_sharpwsus_*
Falsepositives:
  -Unknown
Level: high