Suspicious Debugger Registration Cmdline

 Original Source: [Sigma source]
Title: Suspicious Debugger Registration Cmdline
Status: test
Description:Detects the registration of a debugger for a program that is available in the logon screen (sticky key backdoor).
References:
  -https://blogs.technet.microsoft.com/jonathantrull/2016/10/03/detecting-sticky-key-backdoors/
  -https://bazaar.abuse.ch/sample/6f3aa9362d72e806490a8abce245331030d1ab5ac77e400dd475748236a6cc81/
Author: Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro
Date: 2019-09-06
modified:2022-08-06
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.t1546.008'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection1:
    CommandLine|contains: '\CurrentVersion\Image File Execution Options\'
  selection2:
    CommandLine|contains:
      -'sethc.exe'
      -'utilman.exe'
      -'osk.exe'
      -'magnify.exe'
      -'narrator.exe'
      -'displayswitch.exe'
      -'atbroker.exe'
      -'HelpPane.exe'

  condition:all of selection*
Falsepositives:
  -Unknown
Level: high