Use of Remote.exe

 Original Source: [Sigma source]
Title: Use of Remote.exe
Status: test
Description:Remote.exe is part of WinDbg in the Windows SDK and can be used for AWL bypass and running remote files.
References:
  -https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/
Author: Christopher Peacock @SecurePeacock, SCYTHE @scythe_io
Date: 2022-06-02
modified:None
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1127'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
Image|endswith:'\remote.exe' OriginalFileName:'remote.exe'   condition:selection
Falsepositives:
  -Approved installs of Windows SDK with Debugging Tools for Windows (WinDbg).
Level: medium