Files
blue-team-tools/rules/windows/powershell/powershell_script/posh_ps_susp_wallpaper.yml
T

31 lines
1.1 KiB
YAML
Raw Normal View History

2021-12-26 12:09:42 +01:00
title: Replace Desktop Wallpaper by Powershell
id: c5ac6a1e-9407-45f5-a0ce-ca9a0806a287
2023-01-27 06:48:34 +01:00
status: test
2021-12-26 12:09:42 +01:00
description: |
An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users.
This may take the form of modifications to internal websites, or directly to user systems with the replacement of the desktop wallpaper
references:
2022-07-11 14:11:53 +01:00
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1491.001/T1491.001.md
2022-10-26 09:43:39 +02:00
author: frack113
date: 2021-12-26
2022-10-26 09:43:39 +02:00
tags:
- attack.impact
- attack.t1491.001
2021-12-26 12:09:42 +01:00
logsource:
product: windows
category: ps_script
2023-01-04 17:49:32 +01:00
definition: 'Requirements: Script Block Logging must be enabled'
2021-12-26 12:09:42 +01:00
detection:
selection_1:
ScriptBlockText|contains|all:
- 'Get-ItemProperty'
- 'Registry::'
2022-07-11 14:11:53 +01:00
- 'HKEY_CURRENT_USER\Control Panel\Desktop\'
2021-12-26 12:09:42 +01:00
- 'WallPaper'
selection_2:
ScriptBlockText|contains: SystemParametersInfo(20,0,*,3)
condition: 1 of selection_*
falsepositives:
- Unknown
level: low