Elastic Defend high stable eql

AMSI Bypass from Suspicious Module

Identifies attempts to modify the permissions or write to Microsoft Anti Malware Scan Interface DLL from unsigned module.

View Source

Detection Logic

api where process.Ext.api.metadata.target_address_name like "amsi.dll*" and
 ((process.Ext.api.name in ("VirtualProtect", "VirtualProtectEx") and process.Ext.api.parameters.protection like "?W*") or
  process.Ext.api.name == "WriteProcessMemory") and
  not process.thread.Ext.call_stack_final_user_module.protection_provenance like "Kernel*" and
  not process.thread.Ext.call_stack_final_user_module.name in ("Kernel", "Unknown", "Undetermined") and
  not process.thread.Ext.call_stack_final_user_module.hash.sha256 in
                                  ("2ef4add3ecdc20e1234b0c3fa034cf110f5dfc01355f81ed773f797fcdc6a375",
                                   "c2710daef53ff962522ec1e7e05cdc7147db3371dfbc71cb1cf7afe6382451e5",
                                   "15dd664aee6bfd3cbe0a967d160f4f4b37fe3e8aef88dfb4547e77292226c0c4",
                                   "a121de30d1b8cdf66d886f8cd02b4a35d477f2638d616673da76716a9466cae7",
                                   "ce0644768cd505a8975d897a560186011fbcd2cbd6b309eb0688fc4d816a3451",
                                   "23217cdb3ff108ee4e099f61afa6e33f65675ae0c25d7cc0a30554deca1b33dc",
                                   "d0c7983d45bbbe52e10aa461226cef4049d30778a5d03c9663251edbcea5bd6e",
                                   "b6f6b9f49c60a2230cbf1a3449c85434b70a3b46cc3727da3ef265ba46ac4967",
                                   "902080ae0b0348dca5d526b8cefee280fec0e4eb7299af211ad522e6644032f4",
                                   "5eea4cecd56c5c12f748a2c06729448419ca4deec2410314b6e9d184ecf64bad",
                                   "384c31b964bac7f60c637ed032d735537adebf3611f78637887d042330655f24",
                                   "4776e752dab37e0540f4f3b66a6686e549a9eba42ddfe2f22ee8bcd8e11d215e",
                                   "3505e9318d1ca3472c7708ebaa1753b5cc0eda43c6f5210807a9e7ca8673a227",
                                   "1ee57272a271e82eee1aebaab306c403b30a2e9df94ede777f17fe84670e5033") and
  (
   _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature, $entry, $entry.trusted == false or $entry.exists == false) or
   _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature, $entry, $entry.subject_name in ("Microsoft Corporation", "Microsoft Windows", ".NET", "Python Software Foundation"))
  ) and
  not _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature, $entry, $entry.trusted == true and
                  $entry.subject_name in ("Microsoft Windows Hardware Compatibility Publisher",
                                          "Microsoft Windows Software Compatibility Publisher",
                                          "MUSARUBRA US LLC")) and
  not process.thread.Ext.call_stack_final_user_module.path like
                                     ("c:\\windows\\system32\\apphelp.dll",
                                      "c:\\windows\\system32\\lsasrv.dll",
                                      "c:\\windows\\system32\\combase.dll",
                                      "c:\\windows\\system32\\ieadvpack.dll",
                                      "c:\\windows\\syswow64\\*.dll",
                                      "c:\\windows\\microsoft.net\\framework*.dll",
                                      "c:\\windows\\assembly\\nativeimages_*.ni.dll",
                                      "c:\\windows\\winsxs\\temp\\pendingdeletes\\$$deleteme*",
                                      "c:\\windows\\system32\\mrt\\*\\mpengine.dll",
                                      "c:\\windows\\system32\\wbem\\fastprox.dll",
                                      "c:\\windows\\winsxs\\*.dll",
                                      "c:\\program files (x86)\\*",
                                      "c:\\program files\\*",
                                      "c:\\windows\\syswow64\\werfault.exe") and
  not process.thread.Ext.call_stack_final_user_module.protection_provenance_path like
                                                     ("c:\\windows\\microsoft.net\\framework*\\clr.dll",
                                                      "c:\\windows\\syswow64\\combase.dll",
                                                      "c:\\windows\\system32\\combase.dll") and
  not (process.executable : "C:\\Windows\\ccmsetup\\cache\\ccmsetup.exe" and
       process.parent.executable : ("C:\\Windows\\CCM\\CcmEval.exe", "C:\\Program Files\\SMS_CCM\\CcmEval.exe", "C:\\Windows\\CCM\\ccmrepair.exe")) and
  not (process.Ext.api.name == "VirtualProtect" and
       _arraysearch(process.thread.Ext.call_stack, $entry, $entry.symbol_info like ("c:\\windows\\sys?????\\ntdll.dll!LdrLoadDll*", "c:\\windows\\sys?????\\kernelbase.dll!LoadLibrary*")))

Field Validations

Loading…

Comments (0)

Loading comments...