CobaltStrike Service Installations - Security

 Original Source: [Sigma source]
Title: CobaltStrike Service Installations - Security
Status: test
Description:Detects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement
References:
  -https://www.sans.org/webcasts/119395
  -https://www.crowdstrike.com/blog/getting-the-bacon-from-cobalt-strike-beacon/
  -https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/
Author: Florian Roth (Nextron Systems), Wojciech Lesicki
Date: 2021-05-26
modified:2022-11-27
Tags:
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.privilege-escalation'
  • -'attack.lateral-movement'
  • -'attack.t1021.002'
  • -'attack.t1543.003'
  • -'attack.t1569.002'
Logsource:
  • product: windows
  • service: security
  • definition: The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697
Detection:
  event_id:
    EventID: '4697'
  selection1:
    ServiceFileName|contains|all:
      -'ADMIN$'
      -'.exe'

  selection2:
    ServiceFileName|contains|all:
      -'%COMSPEC%'
      -'start'
      -'powershell'

  selection3:
    ServiceFileName|contains: 'powershell -nop -w hidden -encodedcommand'
  selection4:
    ServiceFileName|base64offset|contains: 'IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:'
  condition:event_id and 1 of selection*
Falsepositives:
  -Unknown
Level: high