Files
blue-team-tools/rules/windows/process_creation/proc_creation_win_renamed_ftp.yml
T
Nasreddine Bencherchali 5fd152cd51 feat: more updates
2023-02-07 17:12:26 +01:00

30 lines
755 B
YAML

title: Renamed FTP.EXE Execution
id: 277a4393-446c-449a-b0ed-7fdc7795244c
status: test
description: Detects the execution of a renamed "ftp.exe" binary based on the PE metadata fields
references:
- https://lolbas-project.github.io/lolbas/Binaries/Ftp/
author: Victor Sergeev, oscd.community
date: 2020/10/09
modified: 2023/02/03
tags:
- attack.execution
- attack.t1059
- attack.defense_evasion
- attack.t1202
logsource:
category: process_creation
product: windows
detection:
selection_original:
OriginalFileName: 'ftp.exe'
filter_img:
Image|endswith: '\ftp.exe'
condition: selection_original and not filter_img
fields:
- CommandLine
- ParentImage
falsepositives:
- Unknown
level: medium