Xwizard.EXE Execution From Non-Default Location

 Original Source: [Sigma source]
Title: Xwizard.EXE Execution From Non-Default Location
Status: test
Description:Detects the execution of Xwizard tool from a non-default directory. When executed from a non-default directory, this utility can be abused in order to side load a custom version of "xwizards.dll".
References:
  -https://lolbas-project.github.io/lolbas/Binaries/Xwizard/
  -http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/
Author: Christian Burkard (Nextron Systems)
Date: 2021-09-20
modified:2024-08-15
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
Image|endswith:'\xwizard.exe' OriginalFileName:'xwizard.exe'   filter_main_legit_location:
    Image|startswith:
      -'C:\Windows\System32\'
      -'C:\Windows\SysWOW64\'
      -'C:\Windows\WinSxS\'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Windows installed on non-C drive
Level: high