From 542a901f57cb6fa3f1b41d3bb7b7ee1eced0cb9d Mon Sep 17 00:00:00 2001 From: frack113 <62423083+frack113@users.noreply.github.com> Date: Sun, 30 Jan 2022 12:03:32 +0100 Subject: [PATCH] add win_pc_susp_takeown --- rules/windows/win_pc_susp_takeown.yml | 29 +++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 rules/windows/win_pc_susp_takeown.yml diff --git a/rules/windows/win_pc_susp_takeown.yml b/rules/windows/win_pc_susp_takeown.yml new file mode 100644 index 000000000..962297b44 --- /dev/null +++ b/rules/windows/win_pc_susp_takeown.yml @@ -0,0 +1,29 @@ +title: Suspicious Recursif Takeown +id: 554601fb-9b71-4bcc-abf4-21a611be4fde +status: experimental +description: Adversaries can interact with the DACLs using built-in Windows commands takeown which can grant adversaries higher permissions on specific files and folders +author: frack113 +references: + - https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/takeown + - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1222.001/T1222.001.md#atomic-test-1---take-ownership-using-takeown-utility +date: 2022/01/30 +logsource: + category: process_creation + product: windows +detection: + selection: + Image|endswith: '\takeown.exe' + CommandLine|contains|all: + - '/f ' + - '/r' + condition: selection +fields: + - CommandLine + - ParentCommandLine +falsepositives: + - Scripts created by developers and admins + - Administrative activity +level: medium +tags: + - attack.defense_evasion + - attack.t1222.001