This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential Arbitrary Command Execution Using Msdt.EXE
Original Source:
[Sigma source]
Title:
Potential Arbitrary Command Execution Using Msdt.EXE
Status:
test
Description:
Detects processes leveraging the "ms-msdt" handler or the "msdt.exe" binary to execute arbitrary commands as seen in the follina (CVE-2022-30190) vulnerability
References:
-https://twitter.com/nao_sec/status/1530196847679401984
-https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/
-https://twitter.com/_JohnHammond/status/1531672601067675648
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-05-29
modified:
2024-03-13
Tags:
-'attack.stealth'
-'attack.t1202'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\msdt.exe'
OriginalFileName
:
'msdt.exe'
selection_cmd_inline:
CommandLine|contains
:
'IT_BrowseForFile='
selection_cmd_answerfile_flag:
CommandLine|contains
:
' PCWDiagnostic'
selection_cmd_answerfile_param:
CommandLine|contains|windash
:
' -af '
condition
:
selection_img and (selection_cmd_inline or all of selection_cmd_answerfile_*)
Falsepositives:
-Unknown
Level:
high