MITRE BZAR Indicators for Persistence

 Original Source: [Sigma source]
Title: MITRE BZAR Indicators for Persistence
Status: test
Description:Windows DCE-RPC functions which indicate a persistence techniques on the remote system. All credit for the Zeek mapping of the suspicious endpoint/operation field goes to MITRE.
References:
  -https://github.com/mitre-attack/bzar#indicators-for-attck-persistence
Author: @neu5ron, SOC Prime
Date: 2020-03-19
modified:2021-11-27
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1547.004'
Logsource:
  • product: zeek
  • service: dce_rpc
Detection:
  op1:
    endpoint: 'spoolss'
    operation: 'RpcAddMonitor'
  op2:
    endpoint: 'spoolss'
    operation: 'RpcAddPrintProcessor'
  op3:
    endpoint: 'IRemoteWinspool'
    operation: 'RpcAsyncAddMonitor'
  op4:
    endpoint: 'IRemoteWinspool'
    operation: 'RpcAsyncAddPrintProcessor'
  op5:
    endpoint: 'ISecLogon'
    operation: 'SeclCreateProcessWithLogonW'
  op6:
    endpoint: 'ISecLogon'
    operation: 'SeclCreateProcessWithLogonExW'
  condition:1 of op*
Falsepositives:
  -Windows administrator tasks or troubleshooting
  -Windows management scripts or software
Level: medium