This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potentially Suspicious Child Process Of Regsvr32
Original Source:
[Sigma source]
Title:
Potentially Suspicious Child Process Of Regsvr32
Status:
test
Description:
Detects potentially suspicious child processes of "regsvr32.exe".
References:
-https://redcanary.com/blog/intelligence-insights-april-2022/
-https://www.echotrail.io/insights/search/regsvr32.exe
-https://www.ired.team/offensive-security/code-execution/t1117-regsvr32-aka-squiblydoo
Author:
elhoim, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date:
2022-05-05
modified:
2023-05-26
Tags:
-'attack.stealth'
-'attack.t1218.010'
Logsource:
category: process_creation
product: windows
Detection:
selection:
ParentImage|endswith
:
'\regsvr32.exe'
Image|endswith
:
-'\calc.exe'
-'\cscript.exe'
-'\explorer.exe'
-'\mshta.exe'
-'\net.exe'
-'\net1.exe'
-'\nltest.exe'
-'\notepad.exe'
-'\powershell.exe'
-'\pwsh.exe'
-'\reg.exe'
-'\schtasks.exe'
-'\werfault.exe'
-'\wscript.exe'
filter_main_werfault:
Image|endswith
:
'\werfault.exe'
CommandLine|contains
:
' -u -p '
condition
:
selection and not 1 of filter_main_*
Falsepositives:
-Unlikely, but can rarely occur. Apply additional filters accordingly.
Level:
high