Sdiagnhost Calling Suspicious Child Process

 Original Source: [Sigma source]
Title: Sdiagnhost Calling Suspicious Child Process
Status: test
Description:Detects sdiagnhost.exe calling a suspicious child process (e.g. used in exploits for Follina / CVE-2022-30190)
References:
  -https://twitter.com/nao_sec/status/1530196847679401984
  -https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e
  -https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/
  -https://app.any.run/tasks/f420d295-0457-4e9b-9b9e-6732be227583/
  -https://app.any.run/tasks/c4117d9a-f463-461a-b90f-4cd258746798/
Author: Nextron Systems, @Kostastsale
Date: 2022-06-01
modified:2024-08-23
Tags:
  • -'attack.stealth'
  • -'attack.t1036'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\sdiagnhost.exe'
    Image|endswith:
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\cmd.exe'
      -'\mshta.exe'
      -'\cscript.exe'
      -'\wscript.exe'
      -'\taskkill.exe'
      -'\regsvr32.exe'
      -'\rundll32.exe'
      -'\calc.exe'

  filter_main_cmd_bits:
    Image|endswith: '\cmd.exe'
    CommandLine|contains: 'bits'
  filter_main_powershell_noprofile:
    Image|endswith: '\powershell.exe'
    CommandLine|endswith:
      -'-noprofile -'
      -'-noprofile'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high