Elastic medium stable eql
ImageLoad via Windows Update Auto Update Client
Identifies abuse of the Windows Update Auto Update Client (wuauclt.exe) to load an arbitrary DLL. This behavior is used as a defense evasion technique to blend-in malicious activity with legitimate Windows software.
Detection Logic
process where host.os.type == "windows" and event.type == "start" and
(?process.pe.original_file_name == "wuauclt.exe" or process.name : "wuauclt.exe") and
/* necessary windows update client args to load a dll */
process.args : "/RunHandlerComServer" and process.args : "/UpdateDeploymentProvider" and
/* common paths writeable by a standard user where the target DLL can be placed */
process.args : ("C:\\Users\\*.dll", "C:\\ProgramData\\*.dll", "C:\\Windows\\Temp\\*.dll", "C:\\Windows\\Tasks\\*.dll") Field Validations
Loading…
Comments (0)
Loading comments...