Persistence Via New SIP Provider

 Original Source: [Sigma source]
Title: Persistence Via New SIP Provider
Status: test
Description:Detects when an attacker register a new SIP provider for persistence and defense evasion
References:
  -https://persistence-info.github.io/Data/codesigning.html
  -https://github.com/gtworek/PSBits/tree/master/SIP
  -https://specterops.io/assets/resources/SpecterOps_Subverting_Trust_in_Windows.pdf
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-07-21
modified:2023-08-17
Tags:
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1553.003'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection_root:
    TargetObject|contains:
      -'\SOFTWARE\Microsoft\Cryptography\Providers\'
      -'\SOFTWARE\Microsoft\Cryptography\OID\EncodingType'
      -'\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\'
      -'\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType'

  selection_dll:
    TargetObject|contains:
      -'\Dll'
      -'\$DLL'

  filter:
    Details:
      -'WINTRUST.DLL'
      -'mso.dll'

  filter_poqexec:
    Image: 'C:\Windows\System32\poqexec.exe'
    TargetObject|contains: '\CryptSIPDll'
    Details: 'C:\Windows\System32\PsfSip.dll'
  condition:all of selection_* and not 1 of filter*
Falsepositives:
  -Legitimate SIP being registered by the OS or different software.
Level: medium