MITRE BZAR Indicators for Execution

 Original Source: [Sigma source]
Title: MITRE BZAR Indicators for Execution
Status: test
Description:Windows DCE-RPC functions which indicate an execution techniques on the remote system. All credit for the Zeek mapping of the suspicious endpoint/operation field goes to MITRE
References:
  -https://github.com/mitre-attack/bzar#indicators-for-attck-execution
Author: @neu5ron, SOC Prime
Date: 2020-03-19
modified:2021-11-27
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.t1047'
  • -'attack.t1053.002'
  • -'attack.t1569.002'
Logsource:
  • product: zeek
  • service: dce_rpc
Detection:
  op1:
    endpoint: 'JobAdd'
    operation: 'atsvc'
  op2:
    endpoint: 'ITaskSchedulerService'
    operation: 'SchRpcEnableTask'
  op3:
    endpoint: 'ITaskSchedulerService'
    operation: 'SchRpcRegisterTask'
  op4:
    endpoint: 'ITaskSchedulerService'
    operation: 'SchRpcRun'
  op5:
    endpoint: 'IWbemServices'
    operation: 'ExecMethod'
  op6:
    endpoint: 'IWbemServices'
    operation: 'ExecMethodAsync'
  op7:
    endpoint: 'svcctl'
    operation: 'CreateServiceA'
  op8:
    endpoint: 'svcctl'
    operation: 'CreateServiceW'
  op9:
    endpoint: 'svcctl'
    operation: 'StartServiceA'
  op10:
    endpoint: 'svcctl'
    operation: 'StartServiceW'
  condition:1 of op*
Falsepositives:
  -Windows administrator tasks or troubleshooting
  -Windows management scripts or software
Level: medium