Files
blue-team-tools/rules/windows/process_creation/process_creation_susp_image_missing.yml
T
2021-12-09 16:03:06 +01:00

23 lines
687 B
YAML

title: Execution Of Not Existing File
id: 71158e3f-df67-472b-930e-7d287acaa3e1
status: experimental
description: Checks whether the image specified in a process creation event is not a full, absolute path (caused by process ghosting or other unorthodox methods to start a process)
author: Max Altgelt
date: 2021/12/09
references:
- https://pentestlaboratories.com/2021/12/08/process-ghosting/
tags:
- attack.defense_evasion
logsource:
category: process_creation
product: windows
detection:
image_absolute_path:
Image|contains: '\'
filter:
Image: null
condition: not image_absolute_path and not filter
falsepositives:
- unknown
level: high