Potential WinAPI Calls Via CommandLine

 Original Source: [Sigma source]
Title: Potential WinAPI Calls Via CommandLine
Status: test
Description:Detects the use of WinAPI Functions via the commandline. As seen used by threat actors via the tool winapiexec
References:
  -https://twitter.com/m417z/status/1566674631788007425
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-09-06
modified:2025-03-06
Tags:
  • -'attack.execution'
  • -'attack.t1106'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains:
      -'AddSecurityPackage'
      -'AdjustTokenPrivileges'
      -'Advapi32'
      -'CloseHandle'
      -'CreateProcessWithToken'
      -'CreatePseudoConsole'
      -'CreateRemoteThread'
      -'CreateThread'
      -'CreateUserThread'
      -'DangerousGetHandle'
      -'DuplicateTokenEx'
      -'EnumerateSecurityPackages'
      -'FreeHGlobal'
      -'FreeLibrary'
      -'GetDelegateForFunctionPointer'
      -'GetLogonSessionData'
      -'GetModuleHandle'
      -'GetProcAddress'
      -'GetProcessHandle'
      -'GetTokenInformation'
      -'ImpersonateLoggedOnUser'
      -'kernel32'
      -'LoadLibrary'
      -'memcpy'
      -'MiniDumpWriteDump'
      -'ntdll'
      -'OpenDesktop'
      -'OpenProcess'
      -'OpenProcessToken'
      -'OpenThreadToken'
      -'OpenWindowStation'
      -'PtrToString'
      -'QueueUserApc'
      -'ReadProcessMemory'
      -'RevertToSelf'
      -'RtlCreateUserThread'
      -'secur32'
      -'SetThreadToken'
      -'VirtualAlloc'
      -'VirtualFree'
      -'VirtualProtect'
      -'WaitForSingleObject'
      -'WriteInt32'
      -'WriteProcessMemory'
      -'ZeroFreeGlobalAllocUnicode'

  filter_optional_mpcmdrun:
    Image|endswith: '\MpCmdRun.exe'
    CommandLine|contains: 'GetLoadLibraryWAddress32'
  filter_optional_compatTelRunner:
    ParentImage|endswith: '\CompatTelRunner.exe'
    CommandLine|contains:
      -'FreeHGlobal'
      -'PtrToString'
      -'kernel32'
      -'CloseHandle'

  condition:selection and not 1 of filter_optional_*
Falsepositives:
  -Some legitimate action or applications may use these functions. Investigate further to determine the legitimacy of the activity.
Level: high