From fbbf29fd80805b6f6e4682ae1214384fe63c48ea Mon Sep 17 00:00:00 2001 From: juju4 Date: Sun, 30 Jul 2017 11:10:43 -0400 Subject: [PATCH] suspicious cli escape character rules --- rules/windows/builtin/win_susp_cli_escape.yml | 31 +++++++++++++++++++ 1 file changed, 31 insertions(+) create mode 100644 rules/windows/builtin/win_susp_cli_escape.yml diff --git a/rules/windows/builtin/win_susp_cli_escape.yml b/rules/windows/builtin/win_susp_cli_escape.yml new file mode 100644 index 000000000..601613a1e --- /dev/null +++ b/rules/windows/builtin/win_susp_cli_escape.yml @@ -0,0 +1,31 @@ +title: Detects Suspicious Commandline escape +description: Detects suspicious process that use escape characters +status: experimental +reference: + - https://twitter.com/vysecurity/status/885545634958385153 + - https://twitter.com/Hexacorn/status/885553465417756673 + - https://twitter.com/Hexacorn/status/885570278637678592 + - https://www.fireeye.com/blog/threat-research/2017/06/obfuscation-in-the-wild.html + - http://www.windowsinspired.com/understanding-the-command-line-string-and-arguments-received-by-a-windows-program/ +author: juju4 +logsource: + product: windows + service: security + description: 'Requirements: Audit Policy : Detailed Tracking > Audit Process creation, Group Policy : Administrative Templates\System\Audit Process Creation' +detection: + selection: + EventID: 4688 + CommandLine: + - '^' + - '@' +# 0x002D -, 0x2013 , 0x2014 , 0x2015 ― ... FIXME! how to match hexa form? + - '-' + - '―' + - 'c:/' + - '' + - '^h^t^t^p' + - 'h"t"t"p' + condition: selection +falsepositives: + - False positives depend on scripts and administrative tools used in the monitored environment +level: medium