This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential Provlaunch.EXE Binary Proxy Execution Abuse
Original Source:
[Sigma source]
Title:
Potential Provlaunch.EXE Binary Proxy Execution Abuse
Status:
test
Description:
Detects child processes of "provlaunch.exe" which might indicate potential abuse to proxy execution.
References:
-https://lolbas-project.github.io/lolbas/Binaries/Provlaunch/
-https://twitter.com/0gtweet/status/1674399582162153472
Author:
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel
Date:
2023-08-08
modified:
None
Tags:
-'attack.stealth'
-'attack.t1218'
Logsource:
category: process_creation
product: windows
Detection:
selection:
ParentImage|endswith
:
'\provlaunch.exe'
filter_main_covered_children:
- Image|endswith
:
- '\calc.exe'
- '\cmd.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\notepad.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\regsvr32.exe'
- '\rundll32.exe'
- '\wscript.exe'
- Image|contains
:
- ':\PerfLogs\'
- ':\Temp\'
- ':\Users\Public\'
- '\AppData\Temp\'
- '\Windows\System32\Tasks\'
- '\Windows\Tasks\'
- '\Windows\Temp\'
condition
:
selection and not 1 of filter_main_*
Falsepositives:
-Unknown
Level:
medium