Title:
Elevated System Shell Spawned From Uncommon Parent Location
Status:
test
Description:Detects when a shell program such as the Windows command prompt or PowerShell is launched with system privileges from a uncommon parent location.
References:
-https://github.com/Wh04m1001/SysmonEoP
Author: frack113, Tim Shelton (update fp)
Date: 2022-12-05
modified:2025-03-06
Tags:
- -'attack.privilege-escalation'
- -'attack.execution'
- -'attack.t1059'
Logsource:
- product: windows
- category: process_creation
Detection:
selection_shell:
- Image|endswith:
- '\powershell.exe'
- '\powershell_ise.exe'
- '\pwsh.exe'
- '\cmd.exe'
- OriginalFileName:
- 'PowerShell.EXE'
- 'powershell_ise.EXE'
- 'pwsh.dll'
- 'Cmd.Exe'
selection_user:
User|contains:
-'AUTHORI'
-'AUTORI'
LogonId:
'0x3e7'
filter_main_generic:
ParentImage|contains:
-':\Program Files (x86)\'
-':\Program Files\'
-':\ProgramData\'
-':\Windows\System32\'
-':\Windows\SysWOW64\'
-':\Windows\Temp\'
-':\Windows\WinSxS\'
filter_optional_manageengine:
ParentImage|endswith:
':\ManageEngine\ADManager Plus\pgsql\bin\postgres.exe'
Image|endswith:
'\cmd.exe'
filter_optional_asgard:
CommandLine|contains:
':\WINDOWS\system32\cmd.exe /c "'
CurrentDirectory|contains:
':\WINDOWS\Temp\asgard2-agent\'
filter_optional_ibm_spectrumprotect:
ParentImage|contains:
':\IBM\SpectrumProtect\webserver\scripts\'
CommandLine|contains:
':\IBM\SpectrumProtect\webserver\scripts\'
filter_main_parent_null:
ParentImage:
'None'
filter_main_parent_empty:
ParentImage:
-''
-'-'
condition:
all of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
-Some legitimate applications may spawn shells from uncommon parent locations. Apply additional filters and perform an initial baseline before deploying.
Level:
medium