Skip to content

Nothing#2

Open
anaszahid wants to merge 1 commit intoLogRhythm-Labs:mainfrom
anaszahid:patch-1
Open

Nothing#2
anaszahid wants to merge 1 commit intoLogRhythm-Labs:mainfrom
anaszahid:patch-1

Conversation

@anaszahid
Copy link

title: Parent in Public Folder Suspicious Process
status: experimental
author: florian Roth
description: This rule detects suspicious processes with parent images located in the C:\Users\Public folder
references:

  • https://redcanary.com/blog/blackbyte-ransomware/
    date: 2022/02/25
    logsource:
    category: process_creation
    product: windows
    detection:
    selection:
    ParentImage|startswith: 'C:\Users\Public'
    CommandLine|contains:
    • 'powershell'
    • 'cmd.exe /c '
    • 'cmd /c '
    • 'wscript.exe'
    • 'cscript.exe'
    • 'bitsadmin'
    • 'certutil'
    • 'mshta.exe'
      condition: selection
      fields:
  • ComputerName
  • User
  • CommandLine
    falsepositives:
  • Unknown
    level: high

Nothing
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Comments