Elastic Defend high stable eql

Network Connection via Startup Item

Identifies the execution of an unsigned program or script from the Startup shell folder followed by an immediate network connection. This may indicate the presence of a malicious persistent item.

View Source

Detection Logic

sequence by process.entity_id with maxspan=1m
 [process where event.action == "start" and
  (
   // unsigned program starting from startup folder
   (process.executable : (
    "?:\\Users\\*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*",
    "?:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*")  and
    not process.code_signature.trusted == true) or

    // Scripts starting from startup folder
   (process.name : ("cscript.exe", "wscript.exe", "mshta.exe", "powershell.exe") and
    process.command_line : (
        "*:\\Users\\*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*",
        "*:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*"))
  ) and

  /* ConnectWiseManage - unsigned */
  not process.hash.sha256 : "cac904da410372bcd0797b4bfa402c8f8663040f26e80a435d98d12bd2fa6659"]
 [network where not cidrmatch(destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24",
       "192.0.0.0/29", "192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32",
       "192.0.2.0/24", "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4",
       "100.64.0.0/10", "192.168.0.0/16", "192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1",
       "FE80::/10", "FF00::/8")]

Field Validations

Loading…

Comments (0)

Loading comments...