Using SettingSyncHost.exe as LOLBin

 Original Source: [Sigma source]
Title: Using SettingSyncHost.exe as LOLBin
Status: test
Description:Detects using SettingSyncHost.exe to run hijacked binary
References:
  -https://www.hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin
Author: Anton Kutepov, oscd.community
Date: 2020-02-05
modified:2021-11-27
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.008'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  system_utility:
    Image|startswith:
      -'C:\Windows\System32\'
      -'C:\Windows\SysWOW64\'

  parent_is_settingsynchost:
    ParentCommandLine|contains|all:
      -'cmd.exe /c'
      -'RoamDiag.cmd'
      -'-outputpath'

  condition:not system_utility and parent_is_settingsynchost
Falsepositives:
  -Unknown
Level: high