Files
blue-team-tools/rules/windows/process_creation/proc_creation_win_renamed_ftp.yml
T
2022-11-11 10:03:24 +01:00

30 lines
754 B
YAML

title: Renamed FTP.EXE Binary Execution
id: 277a4393-446c-449a-b0ed-7fdc7795244c
status: test
description: Detects execution of renamed ftp.exe binary based on OriginalFileName field
references:
- https://lolbas-project.github.io/lolbas/Binaries/Ftp/
author: Victor Sergeev, oscd.community
date: 2020/10/09
modified: 2022/11/10
tags:
- attack.execution
- attack.t1059
- attack.defense_evasion
- attack.t1202
logsource:
category: process_creation
product: windows
detection:
selection_original:
OriginalFileName: 'ftp.exe'
filter_img:
Image|endswith: '\ftp.exe'
condition: selection_original and not filter_img
fields:
- CommandLine
- ParentImage
falsepositives:
- Unknown
level: medium