T1047 Wmiprvse Wbemcomn DLL Hijack

 Original Source: [Sigma source]
Title: T1047 Wmiprvse Wbemcomn DLL Hijack
Status: test
Description:Detects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network for a WMI DLL Hijack scenario.
References:
  -https://threathunterplaybook.com/hunts/windows/201009-RemoteWMIWbemcomnDLLHijack/notebook.html
Author: Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR)
Date: 2020-10-12
modified:2022-02-24
Tags:
  • -'attack.execution'
  • -'attack.t1047'
  • -'attack.lateral-movement'
  • -'attack.t1021.002'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '5145'
    RelativeTargetName|endswith: '\wbem\wbemcomn.dll'
  filter:
    SubjectUserName|endswith: '$'
  condition:selection and not filter
Falsepositives:
  -Unknown
Level: high