This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl
Original Source:
[Sigma source]
Title:
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl
Status:
test
Description:
Detects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
References:
-https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404
Author:
Julia Fomina, oscd.community
Date:
2020-10-06
modified:
2022-10-09
Tags:
-'attack.stealth'
-'attack.t1216'
Logsource:
category: process_creation
product: windows
Detection:
contains_format_pretty_arg:
CommandLine|contains
:
-'format:pretty'
-'format:"pretty"'
-'format:"text"'
-'format:text'
image_from_system_folder:
Image|startswith
:
-'C:\Windows\System32\'
-'C:\Windows\SysWOW64\'
contains_winrm:
CommandLine|contains
:
'winrm'
condition
:
contains_winrm and (contains_format_pretty_arg and not image_from_system_folder)
Falsepositives:
-Unlikely
Level:
medium