Malicious Windows Script Components File Execution by TAEF Detection

 Original Source: [Sigma source]
Title: Malicious Windows Script Components File Execution by TAEF Detection
Status: test
Description:Windows Test Authoring and Execution Framework (TAEF) framework allows you to run automation by executing tests files written on different languages (C, C#, Microsoft COM Scripting interfaces Adversaries may execute malicious code (such as WSC file with VBScript, dll and so on) directly by running te.exe
References:
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Te/
  -https://twitter.com/pabraeken/status/993298228840992768
  -https://learn.microsoft.com/en-us/windows-hardware/drivers/taef/
Author: Agro (@agro_sev) oscd.community
Date: 2020-10-13
modified:2021-11-27
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
Image|endswith:'\te.exe' ParentImage|endswith:'\te.exe' OriginalFileName:'\te.exe'   condition:selection
Falsepositives:
  -It's not an uncommon to use te.exe directly to execute legal TAEF tests
Level: low