This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
PUA - NirCmd Execution
Original Source:
[Sigma source]
Title:
PUA - NirCmd Execution
Status:
test
Description:
Detects the use of NirCmd tool for command execution, which could be the result of legitimate administrative activity
References:
-https://www.nirsoft.net/utils/nircmd.html
-https://www.winhelponline.com/blog/run-program-as-system-localsystem-account-windows/
-https://www.nirsoft.net/utils/nircmd2.html#using
Author:
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date:
2022-01-24
modified:
2023-02-13
Tags:
-'attack.execution'
-'attack.t1569.002'
-'attack.s0029'
Logsource:
category: process_creation
product: windows
Detection:
selection_org:
Image|endswith
:
'\NirCmd.exe'
OriginalFileName
:
'NirCmd.exe'
selection_cmd:
CommandLine|contains
:
-' execmd '
-'.exe script '
-'.exe shexec '
-' runinteractive '
combo_exec:
CommandLine|contains
:
-' exec '
-' exec2 '
combo_exec_params:
CommandLine|contains
:
-' show '
-' hide '
condition
:
1 of selection_* or all of combo_*
Falsepositives:
-Legitimate use by administrators
Level:
medium