Potential Command Line Path Traversal Evasion Attempt

 Original Source: [Sigma source]
Title: Potential Command Line Path Traversal Evasion Attempt
Status: test
Description:Detects potential evasion or obfuscation attempts using bogus path traversal via the commandline
References:
  -https://twitter.com/hexacorn/status/1448037865435320323
  -https://twitter.com/Gal_B1t/status/1062971006078345217
Author: Christian Burkard (Nextron Systems)
Date: 2021-10-26
modified:2023-03-29
Tags:
  • -'attack.stealth'
  • -'attack.t1036'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_1:
    Image|contains: '\Windows\'
    CommandLine|contains:
      -'\..\Windows\'
      -'\..\System32\'
      -'\..\..\'

  selection_2:
    CommandLine|contains: '.exe\..\'
  filter_optional_google_drive:
    CommandLine|contains: '\Google\Drive\googledrivesync.exe\..\'
  filter_optional_citrix:
    CommandLine|contains: '\Citrix\Virtual Smart Card\Citrix.Authentication.VirtualSmartcard.Launcher.exe\..\'
  condition:1 of selection_* and not 1 of filter_optional_*
Falsepositives:
  -Google Drive
  -Citrix
Level: medium