This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Debugger Registration Cmdline
Original Source:
[Sigma source]
Title:
Suspicious Debugger Registration Cmdline
Status:
test
Description:
Detects the registration of a debugger for a program that is available in the logon screen (sticky key backdoor).
References:
-https://blogs.technet.microsoft.com/jonathantrull/2016/10/03/detecting-sticky-key-backdoors/
-https://bazaar.abuse.ch/sample/6f3aa9362d72e806490a8abce245331030d1ab5ac77e400dd475748236a6cc81/
Author:
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro
Date:
2019-09-06
modified:
2022-08-06
Tags:
-'attack.persistence'
-'attack.privilege-escalation'
-'attack.t1546.008'
Logsource:
category: process_creation
product: windows
Detection:
selection1:
CommandLine|contains
:
'\CurrentVersion\Image File Execution Options\'
selection2:
CommandLine|contains
:
-'sethc.exe'
-'utilman.exe'
-'osk.exe'
-'magnify.exe'
-'narrator.exe'
-'displayswitch.exe'
-'atbroker.exe'
-'HelpPane.exe'
condition
:
all of selection*
Falsepositives:
-Unknown
Level:
high