This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
New Netsh Helper DLL Registered From A Suspicious Location
Original Source:
[Sigma source]
Title:
New Netsh Helper DLL Registered From A Suspicious Location
Status:
test
Description:
Detects changes to the Netsh registry key to add a new DLL value that is located on a suspicious location. This change might be an indication of a potential persistence attempt by adding a malicious Netsh helper
References:
-https://www.ired.team/offensive-security/persistence/t1128-netsh-helper-dll
-https://pentestlab.blog/2019/10/29/persistence-netsh-helper-dll/
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2023-11-28
modified:
None
Tags:
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.t1546.007'
Logsource:
category: registry_set
product: windows
Detection:
selection_target:
TargetObject|contains
:
'\SOFTWARE\Microsoft\NetSh'
selection_folders_1:
Details|contains
:
-':\Perflogs\'
-':\Users\Public\'
-':\Windows\Temp\'
-'\AppData\Local\Temp\'
-'\Temporary Internet'
selection_folders_2:
- Details|contains|all
:
- ':\Users\'
- '\Favorites\'
- Details|contains|all
:
- ':\Users\'
- '\Favourites\'
- Details|contains|all
:
- ':\Users\'
- '\Contacts\'
- Details|contains|all
:
- ':\Users\'
- '\Pictures\'
condition
:
selection_target and 1 of selection_folders_*
Falsepositives:
-Unknown
Level:
high