PUA - Chisel Tunneling Tool Execution

 Original Source: [Sigma source]
Title: PUA - Chisel Tunneling Tool Execution
Status: test
Description:Detects usage of the Chisel tunneling tool via the commandline arguments
References:
  -https://github.com/jpillora/chisel/
  -https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in/
  -https://blog.sekoia.io/lucky-mouse-incident-response-to-detection-engineering/
Author: Florian Roth (Nextron Systems)
Date: 2022-09-13
modified:2023-02-13
Tags:
  • -'attack.command-and-control'
  • -'attack.t1090.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    Image|endswith: '\chisel.exe'
  selection_param1:
    CommandLine|contains:
      -'exe client '
      -'exe server '

  selection_param2:
    CommandLine|contains:
      -'-socks5'
      -'-reverse'
      -' r:'
      -':127.0.0.1:'
      -'-tls-skip-verify '
      -':socks'

  condition:selection_img or all of selection_param*
Falsepositives:
  -Some false positives may occur with other tools with similar commandlines
Level: high