Title:
Potentially Suspicious Child Process Of VsCode
Status:
test
Description:Detects uncommon or suspicious child processes spawning from a VsCode "code.exe" process. This could indicate an attempt of persistence via VsCode tasks or terminal profiles.
References:
-https://twitter.com/nas_bench/status/1618021838407495681
-https://twitter.com/nas_bench/status/1618021415852335105
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-01-26
modified:2023-10-25
Tags:
- -'attack.execution'
- -'attack.stealth'
- -'attack.t1218'
- -'attack.t1202'
Logsource:
- category: process_creation
- product: windows
Detection:
selection_parent:
ParentImage|endswith:
'\code.exe'
selection_children_images:
Image|endswith:
-'\calc.exe'
-'\regsvr32.exe'
-'\rundll32.exe'
-'\cscript.exe'
-'\wscript.exe'
selection_children_cli:
Image|endswith:
-'\powershell.exe'
-'\pwsh.exe'
-'\cmd.exe'
CommandLine|contains:
-'Invoke-Expressions'
-'IEX'
-'Invoke-Command'
-'ICM'
-'DownloadString'
-'rundll32'
-'regsvr32'
-'wscript'
-'cscript'
selection_children_paths:
Image|contains:
-':\Users\Public\'
-':\Windows\Temp\'
-':\Temp\'
condition:
selection_parent and 1 of selection_children_*
Falsepositives:
-In development environment where VsCode is used heavily. False positives may occur when developers use task to compile or execute different types of code. Remove or add processes accordingly
Level:
medium