This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potentially Suspicious Child Process of KeyScrambler.exe
Original Source:
[Sigma source]
Title:
Potentially Suspicious Child Process of KeyScrambler.exe
Status:
test
Description:
Detects potentially suspicious child processes of KeyScrambler.exe
References:
-https://twitter.com/DTCERT/status/1712785421845790799
Author:
Swachchhanda Shrawan Poudel
Date:
2024-05-13
modified:
None
Tags:
-'attack.persistence'
-'attack.execution'
-'attack.privilege-escalation'
-'attack.stealth'
-'attack.t1203'
-'attack.t1574.001'
Logsource:
category: process_creation
product: windows
Detection:
selection_parent:
ParentImage|endswith
:
'\KeyScrambler.exe'
selection_binaries:
- Image|endswith
:
- '\cmd.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\regsvr32.exe'
- '\rundll32.exe'
- '\wscript.exe'
- OriginalFileName
:
- 'Cmd.Exe'
- 'cscript.exe'
- 'mshta.exe'
- 'PowerShell.EXE'
- 'pwsh.dll'
- 'regsvr32.exe'
- 'RUNDLL32.EXE'
- 'wscript.exe'
condition
:
all of selection_*
Falsepositives:
-Unknown
Level:
medium