Google Chronicle unknown experimental yara-l
mitre_attack_T1548_002_windows_uac_bypass
Net use commands for SMB/Windows admin shares
Detection Logic
/*
* Copyright 2021 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* https://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES
OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
rule mitre_attack_T1548_002_windows_uac_bypass
{
meta:
author = "Google Cloud Security"
description = "Net use commands for SMB/Windows admin shares"
reference = "https://attack.mitre.org/techniques/T1021/002/"
yara_version = "YL2.0"
rule_version = "1.0"
events:
(
$e1.metadata.event_type = "PROCESS_LAUNCH" and
re.regex($e1.principal.process.command_line, `reg\.exe add hkcu\\software\\classes\\mscfile\\shell\\open\\command /ve /d.* /f`) nocase
)
or
(
re.regex($e1.principal.process.command_line, `powershell.exe`) nocase and
re.regex($e1.target.registry.registry_key, `\\software\\classes\\mscfile\\shell\\open\\command`) nocase
)
condition:
$e1
} Field Validations
Loading…
Comments (0)
Loading comments...