Title:Suspicious Persistence Via VMwareToolBoxCmd.EXE VM State Change Script Status:test Description:Detects execution of the "VMwareToolBoxCmd.exe" with the "script" and "set" flag to setup a specific script that's located in a potentially suspicious location to run for a specific VM state References: -https://bohops.com/2021/10/08/analyzing-and-detecting-a-vmtools-persistence-technique/ Author: Nasreddine Bencherchali (Nextron Systems) Date: 2023-06-14 modified:None Tags:
-'attack.execution'
-'attack.persistence'
-'attack.t1059'
Logsource:
category: process_creation
product: windows
Detection: selection_bin_img: Image|endswith:'\VMwareToolBoxCmd.exe'OriginalFileName:'toolbox-cmd.exe'selection_bin_cli: CommandLine|contains|all: -' script ' -' set '