Elastic Defend high stable eql

Windows Console Execution from Unbacked Memory

Identifies the creation of a Windows console host process where the creating thread's stack contains frames pointing outside any known executable image. This may be indicative of the use of a built-in Windows shell from an injected process.

View Source

Detection Logic

sequence with maxspan=5m
[process where event.action == "start" and process.parent.executable != null and
 process.parent.thread.Ext.call_stack_contains_unbacked == true and
 (process.executable : "?:\\Windows\\Sys*\\conhost.exe" and process.args : "0xffffffff") and
  process.parent.thread.Ext.call_stack_summary :
               ("ntdll.dll
| kernelbase.dll
| Unbacked",
                "ntdll.dll
| wow64.dll
| wow64cpu.dll
| wow64.dll
| ntdll.dll
| kernelbase.dll
| Unbacked",
                "ntdll.dll
| wow64.dll
| wow64cpu.dll
| wow64.dll
| ntdll.dll
| kernelbase.dll
| Unbacked
| kernel32.dll
| ntdll.dll") and
  not (user.id == "S-1-5-18" and
       process.parent.executable :
                     ("?:\\ProgramData\\*.exe",
                      "?:\\Program Files\\*.exe",
                      "?:\\Program Files (x86)\\*.exe",
                      "?:\\Windows\\LTSvc\\LTSVC.exe",
                      "?:\\Windows\\System32\\msiexec.exe",
                      "C:\\Windows\\_ScriptingFramework\\Modul\\Engine.exe",
                      "C:\\Windows\\_ScriptingFramework\\Modul\\ScriptingFrameworkEngine.exe",
                      "C:\\Windows\\SysWOW64\\SmartDeploy\\ClientService.exe",
                      "I:\\RSA\\Microsoft Azure Recovery Services Agent\\bin\\cbengine.exe",
                      "C:\\Drivers\\Nord\\NordSec ThreatProtection\\nordsec-threatprotection-service.exe")) and
  not (process.parent.executable : "?:\\Windows\\System32\\WindowsPowerShell\\*\\powershell.exe" and user.id : "S-1-5-18" and
       process.code_signature.trusted == true) and
  not (process.code_signature.subject_name : "ProVation Medical" and process.code_signature.trusted == true) and
  not (process.parent.code_signature.subject_name in ("UiPath, Inc.", "QSR International Pty Ltd") and process.parent.code_signature.trusted == true) and
  not (process.parent.code_signature.subject_name : "Microsoft Corporation" and
       process.parent.code_signature.trusted == true and
       process.parent.executable : ("?:\\*\\Microsoft.SQLServer.*.Express.*.exe",
                                     "?:\\*\\SQL*-SSEI-Expr.exe")) and
  not process.parent.executable :
                    ("?:\\Packages\\Plugins\\Microsoft.GuestConfiguration.ConfigurationforWindows\\*\\gc_service.exe",
                     "?:\\Windows\\System32\\wsmprovhost.exe",
                     "?:\\Program Files (x86)\\Wondershare\\*.exe",
                     "?:\\Windows\\System32\\drivers\\*.exe",
                     "?:\\Program Files*\\Cloudflare\\*.exe",
                     "?:\\Program Files (x86)\\Universal\\Universal.Server.exe",
                     "?:\\Program Files*\\Listary\\Listary.exe",
                     "?:\\Program Files*\\ExpressConnect\\ECDBWMService.exe",
                     "?:\\ProVation\\Utilities\\ProVation.DataExport\\ProVation.DataExport.exe",
                     "?:\\Windows\\System32\\WindowsPowerShell\\*\\powershell_ise.exe",
                     "?:\\WINDOWS\\_ScriptingFramework\\Modul\\Engine.exe",
                     "?:\\Program Files\\Citrix\\Telemetry Service\\TelemetryService.exe",
                     "?:\\ProVation\\Utilities\\Database Utilities\\ProVation.DataExport.exe",
                     "?:\\Program Files*\\UiPath\\Studio\\UiPath.Studio.Project.exe",
                     "?:\\Program Files*\\Microsoft System Center\\Operations Manager\\Server\\MonitoringHost.exe",
                     "?:\\Program Files (x86)\\Canfield Scientific Inc\\PortalService\\CanfieldRegister.exe",
                     "?:\\Program Files*\\Microsoft System Center\\Operations Manager\\Server\\MonitoringHost.exe",
                     "?:\\Drivers\\MITS_FATClient_SupportTool\\MITS_FATClient_SupportTool_admin.exe",
                     "?:\\Program Files*\\Microsoft Visual Studio\\*\\Community\\Common?\\IDE\\devenv.exe",
                     "?:\\Program Files\\ObserveIT\\WebsiteCat\\WebsiteCat.Manager.exe",
                     "?:\\Program Files\\Microsoft Azure Active Directory Connect\\AzureADConnect.exe",
                     "?:\\Program Files (x86)\\vMix\\vMix64.exe",
                     "?:\\Work\\HP DIAG TOOL\\ImageDiags.exe",
                     "C:\\Work\\ImageDiags.exe",
                     "?:\\Program Files (x86)\\Driver Support One\\DSOneWeb.exe",
                     "?:\\Program Files (x86)\\Team Shinkansen\\Hakchi2 CE\\hakchi.exe",
                     "?:\\Program Files (x86)\\HP DIAG TOOL\\ImageDiags.exe",
                     "?:\\ProVation\\Utilities\\Database Utilities\\ProVation.DataExport19c\\ProVation.DataExport.exe",
                     "?:\\Program Files\\WindowsApps\\*\\DCv2\\DCv2.exe",
                     "?:\\Users\\*\\Desktop\\HP DIAG TOOL\\ImageDiags.exe",
                     "?:\\ProVation\\Utilities\\Database Utilities\\ProVation.DataExport*\\ProVation.DataExport.exe",
                     "\\Device\\Mup\\*\\Release\\CorrespondanceDownload.vshost.exe",
                     "?:\\Users\\*\\AppData\\Local\\Programs\\UiPath\\Studio\\UiPath.Studio.Project.exe",
                     "D:\\*\\Exporter\\bin\\Debug\\Exporter.vshost.exe",
                     "C:\\Windows\\SysWOW64\\SmartDeploy\\ClientService.exe",
                     "C:\\Program Files\\QSR\\NVivo ??\\NVivo.exe",
                     "C:\\Program Files\\McCormick Systems\\McCormick Estimating\\MaintenanceUtility.exe",
                     "D:\\PROGRAMS\\UiPath\\Studio\\UiPath.Studio.Project.exe",
                     "C:\\Users\\*\\AppData\\Roaming\\GWP\\MSOffice-AddIns\\Deploy-MSOfficeAddIns.exe",
                     "C:\\Program Files\\Devolutions\\Remote Desktop Manager\\RemoteDesktopManager.exe",
                     "C:\\Program Files\\QSR\\NVivo 14\\NVivo.exe",
                     "C:\\Program Files (x86)\\Genetec SV Control Panel\\Control Panel\\SVControlPanel.exe",
                     "D:\\PROGRAMS\\UiPath\\Studio\\UiPath.Studio.Project.exe",
                     "C:\\Program Files (x86)\\Chocolatey GUI\\ChocolateyGui.exe",
                     "C:\\Program Files\\Royal TS V7\\RoyalTS.exe",
                     "C:\\Program Files\\QSR\\NVivo ??\\NVivo.exe",
                     "C:\\Program Files\\Password Safe and Repository*\\PSRServer.exe",
                     "C:\\Program Files\\WindowsApps\\Microsoft.GetHelp_*\\GetHelp.exe", 
                     "C:\\Program Files\\WindowsApps\\Microsoft.DesktopAppInstaller_*\\DotNet\\ConfigurationRemotingServer.exe",
                     "C:\\Program Files (x86)\\CentraStage\\CagService.exe", 
                     "D:\\Microsoft Azure\\Microsoft Azure Recovery Services Agent\\bin\\cbengine.exe", 
                     "C:\\Program Files (x86)\\BMW\\ISPI\\ISVM\\IMIBNext\\Ediabas\\bin\\EbasServer.exe", 
                     "C:\\Program Files\\ASUS\\ASUS VeriView\\ASUSEventClient.exe", 
                     "C:\\Program Files (x86)\\Kovai Ltd\\BizTalk360\\Service\\BHMCollect.exe", 
                     "C:\\Program Files\\Common Files\\eClinicalWorks\\plugin\\WinProjectE.exe", 
                     "C:\\Program Files (x86)\\BizTalkHealthMonitor\\BHMCollect.exe", 
                     "?:\\Program Files (x86)\\Welch Allyn\\Connex\\Server\\*\\DataBaseInstaller\\DatabaseInstaller.exe") and
  not _arraysearch(process.parent.thread.Ext.call_stack, $entry,
                   $entry.callsite_trailing_bytes :
                              ("c6460c01833d*e85ff0f95c00fb6c00fb6c0c6460c01488b559048895610488d65c85b5e5f415c415d415e415f",
                               "*48895610488d65c85b5e5f415c415d415e415f5dc30000001910090010c20c300b60*",
                               "*95c00fb6c0488b5588488956104883c4785b5e5f415c41*",
                               "c6460c01833d9c8c755e007406ff15a495755e85c00f95c00fb6c00fb6c0c6460c01488b559048895610488d65c85b5e5f415c415d415e415f5dc31910090010"))

  ] by process.parent.entity_id
[network where true] by process.entity_id

Field Validations

Loading…

Comments (0)

Loading comments...