This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Process Created Via Wmic.EXE
Original Source:
[Sigma source]
Title:
Suspicious Process Created Via Wmic.EXE
Status:
test
Description:
Detects WMIC executing "process call create" with suspicious calls to processes such as "rundll32", "regsrv32", etc.
References:
-https://thedfirreport.com/2020/10/08/ryuks-return/
-https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker
Author:
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date:
2020-10-12
modified:
2023-02-14
Tags:
-'attack.execution'
-'attack.t1047'
Logsource:
category: process_creation
product: windows
Detection:
selection:
CommandLine|contains|all
:
-'process '
-'call '
-'create '
CommandLine|contains
:
-'rundll32'
-'bitsadmin'
-'regsvr32'
-'cmd.exe /c '
-'cmd.exe /k '
-'cmd.exe /r '
-'cmd /c '
-'cmd /k '
-'cmd /r '
-'powershell'
-'pwsh'
-'certutil'
-'cscript'
-'wscript'
-'mshta'
-'\Users\Public\'
-'\Windows\Temp\'
-'\AppData\Local\'
-'%temp%'
-'%tmp%'
-'%ProgramData%'
-'%appdata%'
-'%comspec%'
-'%localappdata%'
condition
:
selection
Falsepositives:
-Unknown
Level:
high