Hayabusa medium test sigma
Uncommon Service Installation Image Path
Detects uncommon service installation commands by looking at suspicious or uncommon image path values containing references to encoded powershell commands, temporary paths, etc.
Detection Logic
{
"system": {
"Channel": "System"
},
"selection": {
"Provider_Name": "Service Control Manager",
"EventID": 7045
},
"suspicious_paths": {
"ImagePath
| contains": [
"\\\\\\\\.\\\\pipe",
"\\Users\\Public\\",
"\\Windows\\Temp\\"
]
},
"suspicious_encoded_flag": {
"ImagePath
| contains": " -e"
},
"suspicious_encoded_keywords": {
"ImagePath
| contains": [
" aQBlAHgA",
" aWV4I",
" IAB",
" JAB",
" PAA",
" SQBFAFgA",
" SUVYI"
]
},
"filter_optional_thor_remote": {
"ImagePath
| startswith": "C:\\WINDOWS\\TEMP\\thor10-remote\\thor64.exe"
},
"filter_main_defender_def_updates": {
"ImagePath
| startswith": "C:\\ProgramData\\Microsoft\\Windows Defender\\Definition Updates\\"
},
"condition": "system and (selection and ( suspicious_paths or all of suspicious_encoded_* ) and not 1 of filter_main_* and not 1 of filter_optional_*)"
} False Positives
- ⚠ Unknown
Field Validations
Loading…
Comments (0)
Loading comments...