Elastic Defend high stable eql

Image Load via Synthetic Stack Spoofing

Detects attempts to load a networking module from a potentially altered call stack in order to conceal the true source of the call.

View Source

Detection Logic

library where
dll.name : ("wininet.dll", "ws2_32.dll", "dnsapi.dll", "winhttp.dll", "clr.dll", "netapi32.dll",
                "mscorwks.dll", "System.*.dll", "mscorlib*.dll", "Microsoft.PowerShell.Security*.dll",
                "Microsoft.PowerShell.ConsoleHost*.dll", "wmiutils.dll", "fastprox.dll", "wbemprox.dll",
                "vaultcli.dll", "taskschd.dll", "dsquery.dll", "mstscax.dll", "ntdll.dll", "wldap32.dll",
                "wtsapi32.dll", "psapi.dll") and
process.thread.Ext.call_stack_summary like "ntdll.dll
| kernel32.dll*" and
 
  /* JMP gadget in kernel32 */
  _arraysearch(process.thread.Ext.call_stack, $entry, $entry.symbol_info regex~ """.*system32\\kernel32.dll!(A
| [C-Z]).+""") and
  _arraysearch(process.thread.Ext.call_stack, $entry, $entry.symbol_info : "?:\\Windows\\System32\\ntdll.dll!LdrLoadDll*") and
   not process.thread.Ext.call_stack_summary like "ntdll.dll
| kernel32.dll
| mso40uiwin32client.dll
| mso98win32client.dll
| mso.dll
| *" and
   not  _arraysearch(process.thread.Ext.call_stack, $entry, 
                   $entry.symbol_info : ("*kernel32.dll!CreateProcess*", "*kernel32.dll!GetDateFormatWWorker*", 
                                         "*kernel32.dll!WerpLaunchAeDebug*", "*kernel32.dll!BaseDllReadWriteIniFile*", 
                                         "*kernel32.dll!GlobalReAlloc*", "*kernel32.dll!CreateToolhelp32Snapshot*", 
                                         "*kernel32.dll!Wow64SetThreadContext*", "*kernel32.dll!ExitProcess*", "*kernel32.dll!WinExec*",
                                         "*kernel32.dll!CallbackMayRunLong*", "*kernel32.dll!BaseGenerateAppCompatData*", 
                                         "*mpclient.dll!MpUpdateServicePingRpc*", "*chrome.exe!IsSandboxedProcess*",
                                         "*kernel32.dll!CreateActCtxWWorker*", "*kernel32.dll!Sleep*",
                                         "*kernel32.dll!BasepCheckAppCompat*", "*kernel32.dll!AddAtomW*",
                                         "*\\kernel32.dll!lstrlenW*", "*\\kernel32.dll!FindActCtxSectionGuidWorker*",
                                         "*\\kernel32.dll!OpenPrivateNamespaceW*", "*\\kernel32.dll!DeactivateActCtxWorke*",
                                         "c:\\windows\\system32\\kernel32.dll!QuirkIsEnabled3Worker*",
                                         "C:\\Windows\\System32\\kernel32.dll!GetQueuedCompletionStatus*",
                                         "*\\ntdll.dll!RtlFormatMessageEx*", "*kernel32.dll!GetQueuedCompletionStatus*"))

Field Validations

Loading…

Comments (0)

Loading comments...