This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Serv-U Process Pattern
Original Source:
[Sigma source]
Title:
Suspicious Serv-U Process Pattern
Status:
test
Description:
Detects a suspicious process pattern which could be a sign of an exploited Serv-U service
References:
-https://www.microsoft.com/security/blog/2021/07/13/microsoft-discovers-threat-actor-targeting-solarwinds-serv-u-software-with-0-day-exploit/
Author:
Florian Roth (Nextron Systems)
Date:
2021-07-14
modified:
2022-07-14
Tags:
-'attack.credential-access'
-'attack.t1555'
-'cve.2021-35211'
Logsource:
category: process_creation
product: windows
Detection:
selection:
ParentImage|endswith
:
'\Serv-U.exe'
Image|endswith
:
-'\cmd.exe'
-'\powershell.exe'
-'\pwsh.exe'
-'\wscript.exe'
-'\cscript.exe'
-'\sh.exe'
-'\bash.exe'
-'\schtasks.exe'
-'\regsvr32.exe'
-'\wmic.exe'
-'\mshta.exe'
-'\rundll32.exe'
-'\msiexec.exe'
-'\forfiles.exe'
-'\scriptrunner.exe'
condition
:
selection
Falsepositives:
-Legitimate uses in which users or programs use the SSH service of Serv-U for remote command execution
Level:
high