Elastic Defend high stable eql
Network Connection via Startup Item
Identifies the execution of an unsigned program or script from the Startup shell folder followed by an immediate network connection. This may indicate the presence of a malicious persistent item.
Detection Logic
sequence by process.entity_id with maxspan=1m
[process where event.action == "start" and
(
// unsigned program starting from startup folder
(process.executable : (
"?:\\Users\\*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*",
"?:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*") and
not process.code_signature.trusted == true) or
// Scripts starting from startup folder
(process.name : ("cscript.exe", "wscript.exe", "mshta.exe", "powershell.exe") and
process.command_line : (
"*:\\Users\\*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*",
"*:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*"))
) and
/* ConnectWiseManage - unsigned */
not process.hash.sha256 : "cac904da410372bcd0797b4bfa402c8f8663040f26e80a435d98d12bd2fa6659"]
[network where not cidrmatch(destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24",
"192.0.0.0/29", "192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32",
"192.0.2.0/24", "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4",
"100.64.0.0/10", "192.168.0.0/16", "192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1",
"FE80::/10", "FF00::/8")] Field Validations
Loading…
Comments (0)
Loading comments...