This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - SharpWSUS/WSUSpendu Execution
Original Source:
[Sigma source]
Title:
HackTool - SharpWSUS/WSUSpendu Execution
Status:
test
Description:
Detects the execution of SharpWSUS or WSUSpendu, utilities that allow for lateral movement through WSUS. Windows Server Update Services (WSUS) is a critical component of Windows systems and is frequently configured in a way that allows an attacker to circumvent internal networking limitations.
References:
-https://labs.nettitude.com/blog/introducing-sharpwsus/
-https://github.com/nettitude/SharpWSUS
-https://web.archive.org/web/20210512154016/https://github.com/AlsidOfficial/WSUSpendu/blob/master/WSUSpendu.ps1
Author:
@Kostastsale, Nasreddine Bencherchali (Nextron Systems)
Date:
2022-10-07
modified:
2024-08-23
Tags:
-'attack.execution'
-'attack.lateral-movement'
-'attack.t1210'
Logsource:
product: windows
category: process_creation
Detection:
selection_wsuspendu_inject:
CommandLine|contains
:
' -Inject '
selection_wsuspendu_payload:
CommandLine|contains
:
-' -PayloadArgs '
-' -PayloadFile '
selection_sharpwsus_commands:
CommandLine|contains
:
-' approve '
-' create '
-' check '
-' delete '
selection_sharpwsus_flags:
CommandLine|contains
:
-' /payload:'
-' /payload='
-' /updateid:'
-' /updateid='
condition
:
all of selection_wsuspendu_* or all of selection_sharpwsus_*
Falsepositives:
-Unknown
Level:
high