Find sigma rule
Attack: Masquerading: Rename System Utilities
Adversaries may rename legitimate system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control mechanisms may be in place for system utilities adversaries are capable of abusing. (Citation: LOLBAS Main Site) It may be possible to bypass those security mechanisms by renaming the utility prior to utilization (ex: rename rundll32.exe
). (Citation: Elastic Masquerade Ball) An alternative case occurs when a legitimate utility is copied or moved to a different directory and renamed to avoid detections based on system utilities executing from non-standard paths. (Citation: F-Secure CozyDuke)
MITRE
Tactic
- defense-evasion
technique
- T1036.003
Test : Malicious process Masquerading as LSM.exe
OS
- windows
Description:
Detect LSM running from an incorrect directory and an incorrect service account This works by copying cmd.exe to a file, naming it lsm.exe, then copying a file to the C:\ folder.
Upon successful execution, cmd.exe will be renamed as lsm.exe and executed from non-standard path.
Executor
command_prompt
Sigma Rule
-
proc_creation_win_susp_copy_system_dir.yml (id: fff9d2b7-e11c-4a69-93d3-40ef66189767)
-
file_event_win_creation_system_file.yml (id: d5866ddf-ce8f-4aea-b28e-d96485a20d3d)
-
proc_creation_win_susp_system_exe_anomaly.yml (id: e4a6b256-3e47-40fc-89d2-7a477edd6915)
-
proc_creation_win_renamed_binary.yml (id: 36480ae1-a1cb-4eaa-a0d6-29801d7e9142)