Potentially Suspicious Child Process Of VsCode

 Original Source: [Sigma source]
Title: Potentially Suspicious Child Process Of VsCode
Status: test
Description:Detects uncommon or suspicious child processes spawning from a VsCode "code.exe" process. This could indicate an attempt of persistence via VsCode tasks or terminal profiles.
References:
  -https://twitter.com/nas_bench/status/1618021838407495681
  -https://twitter.com/nas_bench/status/1618021415852335105
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-01-26
modified:2023-10-25
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1218'
  • -'attack.t1202'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_parent:
    ParentImage|endswith: '\code.exe'
  selection_children_images:
    Image|endswith:
      -'\calc.exe'
      -'\regsvr32.exe'
      -'\rundll32.exe'
      -'\cscript.exe'
      -'\wscript.exe'

  selection_children_cli:
    Image|endswith:
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\cmd.exe'

    CommandLine|contains:
      -'Invoke-Expressions'
      -'IEX'
      -'Invoke-Command'
      -'ICM'
      -'DownloadString'
      -'rundll32'
      -'regsvr32'
      -'wscript'
      -'cscript'

  selection_children_paths:
    Image|contains:
      -':\Users\Public\'
      -':\Windows\Temp\'
      -':\Temp\'

  condition:selection_parent and 1 of selection_children_*
Falsepositives:
  -In development environment where VsCode is used heavily. False positives may occur when developers use task to compile or execute different types of code. Remove or add processes accordingly
Level: medium