Abused Debug Privilege by Arbitrary Parent Processes

 Original Source: [Sigma source]
Title: Abused Debug Privilege by Arbitrary Parent Processes
Status: test
Description:Detection of unusual child processes by different system processes
References:
  -https://image.slidesharecdn.com/kheirkhabarovoffzonefinal-181117201458/95/hunting-for-privilege-escalation-in-windows-environment-74-638.jpg
Author: Semanur Guneysu @semanurtg, oscd.community
Date: 2020-10-28
modified:2022-11-11
Tags:
  • -'attack.privilege-escalation'
  • -'attack.t1548'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_parent:
    ParentImage|endswith:
      -'\winlogon.exe'
      -'\services.exe'
      -'\lsass.exe'
      -'\csrss.exe'
      -'\smss.exe'
      -'\wininit.exe'
      -'\spoolsv.exe'
      -'\searchindexer.exe'

    User|contains:
      -'AUTHORI'
      -'AUTORI'

  selection_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\cmd.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
      - 'Cmd.Exe'
  filter:
    CommandLine|contains|all:
      -' route '
      -' ADD '

  condition:all of selection_* and not filter
Falsepositives:
  -Unknown
Level: high