This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Use of Remote.exe
Original Source:
[Sigma source]
Title:
Use of Remote.exe
Status:
test
Description:
Remote.exe is part of WinDbg in the Windows SDK and can be used for AWL bypass and running remote files.
References:
-https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/
-https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/
Author:
Christopher Peacock @SecurePeacock, SCYTHE @scythe_io
Date:
2022-06-02
modified:
None
Tags:
-'attack.execution'
-'attack.stealth'
-'attack.t1127'
Logsource:
category: process_creation
product: windows
Detection:
selection:
Image|endswith
:
'\remote.exe'
OriginalFileName
:
'remote.exe'
condition
:
selection
Falsepositives:
-Approved installs of Windows SDK with Debugging Tools for Windows (WinDbg).
Level:
medium