Potential Provlaunch.EXE Binary Proxy Execution Abuse

 Original Source: [Sigma source]
Title: Potential Provlaunch.EXE Binary Proxy Execution Abuse
Status: test
Description:Detects child processes of "provlaunch.exe" which might indicate potential abuse to proxy execution.
References:
  -https://lolbas-project.github.io/lolbas/Binaries/Provlaunch/
  -https://twitter.com/0gtweet/status/1674399582162153472
Author: Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel
Date: 2023-08-08
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\provlaunch.exe'
  filter_main_covered_children:
    - Image|endswith:
      - '\calc.exe'
      - '\cmd.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\notepad.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\regsvr32.exe'
      - '\rundll32.exe'
      - '\wscript.exe'
    - Image|contains:
      - ':\PerfLogs\'
      - ':\Temp\'
      - ':\Users\Public\'
      - '\AppData\Temp\'
      - '\Windows\System32\Tasks\'
      - '\Windows\Tasks\'
      - '\Windows\Temp\'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: medium