This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Child Process Created as System
Original Source:
[Sigma source]
Title:
Suspicious Child Process Created as System
Status:
test
Description:
Detection of child processes spawned with SYSTEM privileges by parents with LOCAL SERVICE or NETWORK SERVICE accounts
References:
-https://speakerdeck.com/heirhabarov/hunting-for-privilege-escalation-in-windows-environment
-https://foxglovesecurity.com/2016/09/26/rotten-potato-privilege-escalation-from-service-accounts-to-system/
-https://github.com/antonioCoco/RogueWinRM
-https://twitter.com/Cyb3rWard0g/status/1453123054243024897
Author:
Teymur Kheirkhabarov, Roberto Rodriguez (@Cyb3rWard0g), Open Threat Research (OTR)
Date:
2019-10-26
modified:
2024-12-01
Tags:
-'attack.privilege-escalation'
-'attack.stealth'
-'attack.t1134.002'
Logsource:
category: process_creation
product: windows
definition: Requirements: ParentUser field needs sysmon >= 13.30
Detection:
selection:
ParentUser|contains
:
-'AUTHORI'
-'AUTORI'
ParentUser|endswith
:
-'\NETWORK SERVICE'
-'\LOCAL SERVICE'
User|contains
:
-'AUTHORI'
-'AUTORI'
User|endswith
:
-'\SYSTEM'
-'\Système'
-'\СИСТЕМА'
IntegrityLevel
:
-'System'
-'S-1-16-16384'
filter_rundll32:
Image|endswith
:
'\rundll32.exe'
CommandLine|contains
:
'DavSetCookie'
condition
:
selection and not 1 of filter_*
Falsepositives:
-Unknown
Level:
high