HackTool - winPEAS Execution

 Original Source: [Sigma source]
Title: HackTool - winPEAS Execution
Status: test
Description:WinPEAS is a script that search for possible paths to escalate privileges on Windows hosts. The checks are explained on book.hacktricks.xyz
References:
  -https://github.com/carlospolop/PEASS-ng
  -https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation
Author: Georg Lauenstein (sure[secure])
Date: 2022-09-19
modified:2023-03-23
Tags:
  • -'attack.privilege-escalation'
  • -'attack.discovery'
  • -'attack.t1082'
  • -'attack.t1087'
  • -'attack.t1046'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
OriginalFileName:'winPEAS.exe'     - Image|endswith:
      - '\winPEASany_ofs.exe'
      - '\winPEASany.exe'
      - '\winPEASx64_ofs.exe'
      - '\winPEASx64.exe'
      - '\winPEASx86_ofs.exe'
      - '\winPEASx86.exe'
  selection_cli_option:
    CommandLine|contains:
      -' applicationsinfo'
      -' browserinfo'
      -' eventsinfo'
      -' fileanalysis'
      -' filesinfo'
      -' processinfo'
      -' servicesinfo'
      -' windowscreds'

  selection_cli_dl:
    CommandLine|contains: 'https://github.com/carlospolop/PEASS-ng/releases/latest/download/'
  selection_cli_specific:
ParentCommandLine|endswith:' -linpeas' CommandLine|endswith:' -linpeas'   condition:1 of selection_*
Falsepositives:
  -Unlikely
Level: high