Malicious PE Execution by Microsoft Visual Studio Debugger

 Original Source: [Sigma source]
Title: Malicious PE Execution by Microsoft Visual Studio Debugger
Status: test
Description:There is an option for a MS VS Just-In-Time Debugger "vsjitdebugger.exe" to launch specified executable and attach a debugger. This option may be used adversaries to execute malicious code by signed verified binary. The debugger is installed alongside with Microsoft Visual Studio package.
References:
  -https://twitter.com/pabraeken/status/990758590020452353
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Vsjitdebugger/
  -https://learn.microsoft.com/en-us/visualstudio/debugger/debug-using-the-just-in-time-debugger?view=vs-2019
Author: Agro (@agro_sev), Ensar Şamil (@sblmsrsn), oscd.community
Date: 2020-10-14
modified:2022-10-09
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\vsjitdebugger.exe'
  reduction1:
    Image|endswith: '\vsimmersiveactivatehelper*.exe'
  reduction2:
    Image|endswith: '\devenv.exe'
  condition:selection and not (reduction1 or reduction2)
Falsepositives:
  -The process spawned by vsjitdebugger.exe is uncommon.
Level: medium