Suspicious Child Process Created as System

 Original Source: [Sigma source]
Title: Suspicious Child Process Created as System
Status: test
Description:Detection of child processes spawned with SYSTEM privileges by parents with LOCAL SERVICE or NETWORK SERVICE accounts
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-privilege-escalation-in-windows-environment
  -https://foxglovesecurity.com/2016/09/26/rotten-potato-privilege-escalation-from-service-accounts-to-system/
  -https://github.com/antonioCoco/RogueWinRM
  -https://twitter.com/Cyb3rWard0g/status/1453123054243024897
Author: Teymur Kheirkhabarov, Roberto Rodriguez (@Cyb3rWard0g), Open Threat Research (OTR)
Date: 2019-10-26
modified:2024-12-01
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1134.002'
Logsource:
  • category: process_creation
  • product: windows
  • definition: Requirements: ParentUser field needs sysmon >= 13.30
Detection:
  selection:
    ParentUser|contains:
      -'AUTHORI'
      -'AUTORI'

    ParentUser|endswith:
      -'\NETWORK SERVICE'
      -'\LOCAL SERVICE'

    User|contains:
      -'AUTHORI'
      -'AUTORI'

    User|endswith:
      -'\SYSTEM'
      -'\Système'
      -'\СИСТЕМА'

    IntegrityLevel:
      -'System'
      -'S-1-16-16384'

  filter_rundll32:
    Image|endswith: '\rundll32.exe'
    CommandLine|contains: 'DavSetCookie'
  condition:selection and not 1 of filter_*
Falsepositives:
  -Unknown
Level: high