This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
COM Object Execution via Xwizard.EXE
Original Source:
[Sigma source]
Title:
COM Object Execution via Xwizard.EXE
Status:
test
Description:
Detects the execution of Xwizard tool with the "RunWizard" flag and a GUID like argument. This utility can be abused in order to run custom COM object created in the registry.
References:
-https://lolbas-project.github.io/lolbas/Binaries/Xwizard/
-https://www.elastic.co/guide/en/security/current/execution-of-com-object-via-xwizard.html
-https://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/
Author:
Ensar Şamil, @sblmsrsn, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems)
Date:
2020-10-07
modified:
2024-08-15
Tags:
-'attack.stealth'
-'attack.t1218'
Logsource:
category: process_creation
product: windows
Detection:
selection:
CommandLine
:
'RunWizard'
CommandLine|re
:
'\{[a-fA-F0-9]{8}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{12}\}'
condition
:
selection
Falsepositives:
-Unknown
Level:
medium