Elastic Defend high stable eql
Control Panel Process with Unusual Arguments
Identifies instances of the Control Panel application running with suspicious keywords or paths in the process command line value. Adversaries may abuse Control.exe to proxy execution of malicious code.
Detection Logic
process where event.action == "start" and
(
(process.executable : ("?:\\Windows\\SysWOW64\\control.exe", "?:\\Windows\\System32\\control.exe") and
process.command_line :
("*.jpg*",
"*.png*",
"*.gif*",
"*.bmp*",
"*.jpeg*",
"*.TIFF*",
"*.inf*",
"*.dat*",
"*.cpl:../*",
"*..\\..\\*",
"*/AppData/Local/*",
"*:\\Users\\Public\\*",
"*\\AppData\\Local\\*") and
/* excluding FPs where /name arg is used to specify a control by name */
not (process.args : "/name" and process.args_count >= 2) and
/* excluding system IL to minimize risk of killing system critical execution */
not process.Ext.token.integrity_level_name == "system") or
(process.name : "rundll32.exe" and process.command_line : "*shell32*#*44*" and
not (process.parent.name : "rundll32.exe" and process.parent.command_line : "*Shell32*Control_RunDLL*")) or
(process.name : "rundll32.exe" and process.command_line : "*shell32*#*44*" and
not process.command_line : "*.cpl*" and process.args_count >= 3) or
(process.name : "rundll32.exe" and process.command_line : "*shell32*#*44*" and process.args_count >= 3 and
(process.command_line : ("*/AppData/Local/*", "*:\\Users\\Public\\*", "*\\AppData\\Local\\*", "*:\\ProgramData\\*") or
process.working_directory : ("?:\\Users\\*\\AppData\\Local\\*", "?:\\Users\\Public\\*")))
) and
not (process.name : "rundll32.exe" and process.args : ("OpenAs_RunDLL", "ShellExec_RunDLL")) Field Validations
Loading…
Comments (0)
Loading comments...