Suspicious SysAidServer Child

 Original Source: [Sigma source]
Title: Suspicious SysAidServer Child
Status: test
Description:Detects suspicious child processes of SysAidServer (as seen in MERCURY threat actor intrusions)
References:
  -https://www.microsoft.com/security/blog/2022/08/25/mercury-leveraging-log4j-2-vulnerabilities-in-unpatched-systems-to-target-israeli-organizations/
Author: Florian Roth (Nextron Systems)
Date: 2022-08-26
modified:None
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1210'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith:
      -'\java.exe'
      -'\javaw.exe'

    ParentCommandLine|contains: 'SysAidServer'
  condition:selection
Falsepositives:
  -Unknown
Level: medium