WMI Backdoor Exchange Transport Agent

 Original Source: [Sigma source]
Title: WMI Backdoor Exchange Transport Agent
Status: test
Description:Detects a WMI backdoor in Exchange Transport Agents via WMI event filters
References:
  -https://twitter.com/cglyer/status/1182389676876980224
  -https://twitter.com/cglyer/status/1182391019633029120
Author: Florian Roth (Nextron Systems)
Date: 2019-10-11
modified:2023-02-08
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1546.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\EdgeTransport.exe'
  filter_conhost:
    Image: 'C:\Windows\System32\conhost.exe'
  filter_oleconverter:
    Image|startswith: 'C:\Program Files\Microsoft\Exchange Server\'
    Image|endswith: '\Bin\OleConverter.exe'
  condition:selection and not 1 of filter_*
Falsepositives:
  -Unknown
Level: critical