CobaltStrike Service Installations - System

 Original Source: [Sigma source]
Title: CobaltStrike Service Installations - System
Status: test
Description:Detects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement
References:
  -https://www.sans.org/webcasts/119395
  -https://www.crowdstrike.com/blog/getting-the-bacon-from-cobalt-strike-beacon/
  -https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/
Author: Florian Roth (Nextron Systems), Wojciech Lesicki
Date: 2021-05-26
modified:2022-11-27
Tags:
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.privilege-escalation'
  • -'attack.lateral-movement'
  • -'attack.t1021.002'
  • -'attack.t1543.003'
  • -'attack.t1569.002'
Logsource:
  • product: windows
  • service: system
Detection:
  selection_id:
    Provider_Name: 'Service Control Manager'
    EventID: '7045'
  selection1:
    ImagePath|contains|all:
      -'ADMIN$'
      -'.exe'

  selection2:
    ImagePath|contains|all:
      -'%COMSPEC%'
      -'start'
      -'powershell'

  selection3:
    ImagePath|contains: 'powershell -nop -w hidden -encodedcommand'
  selection4:
    ImagePath|base64offset|contains: 'IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:'
  condition:selection_id and (selection1 or selection2 or selection3 or selection4)
Falsepositives:
  -Unknown
Level: critical