Hayabusa medium test sigma
Unsigned DLL Loaded by Windows Utility
Detects windows utilities loading an unsigned or untrusted DLL. Adversaries often abuse those programs to proxy execution of malicious code.
Detection Logic
{
"image_load": {
"EventID": 7,
"Channel": "Microsoft-Windows-Sysmon/Operational"
},
"selection": {
"Image
| endswith": [
"\\InstallUtil.exe",
"\\RegAsm.exe",
"\\RegSvcs.exe",
"\\regsvr32.exe",
"\\rundll32.exe"
]
},
"filter_main_signed": {
"Signed": "true"
},
"filter_main_sig_status": {
"SignatureStatus": [
"errorChaining",
"errorCode_endpoint",
"errorExpired",
"trusted",
"Valid"
]
},
"filter_main_signed_null": {
"Signed": null
},
"filter_main_signed_empty": {
"Signed": [
"",
"-"
]
},
"filter_main_sig_status_null": {
"SignatureStatus": null
},
"filter_main_sig_status_empty": {
"SignatureStatus": [
"",
"-"
]
},
"filter_main_windows_installer": {
"Image": [
"C:\\Windows\\SysWOW64\\rundll32.exe",
"C:\\Windows\\System32\\rundll32.exe"
],
"ImageLoaded
| startswith": "C:\\Windows\\Installer\\",
"ImageLoaded
| endswith": [
".tmp-\\Microsoft.Deployment.WindowsInstaller.dll",
".tmp-\\Avira.OE.Setup.CustomActions.dll"
]
},
"filter_main_assembly": {
"Image
| startswith": [
"C:\\Windows\\SysWOW64\\",
"C:\\Windows\\System32\\",
"C:\\Windows\\Microsoft.NET\\Framework64"
],
"Image
| endswith": "\\RegAsm.exe",
"ImageLoaded
| endswith": ".dll",
"ImageLoaded
| startswith": "C:\\Windows\\assembly\\NativeImages"
},
"filter_optional_klite_codec": {
"Image": [
"C:\\Windows\\SysWOW64\\regsvr32.exe",
"C:\\Windows\\System32\\regsvr32.exe"
],
"ImageLoaded
| startswith": [
"C:\\Program Files (x86)\\K-Lite Codec Pack\\",
"C:\\Program Files\\K-Lite Codec Pack\\"
]
},
"condition": "image_load and (selection and not 1 of filter_main_* and not 1 of filter_optional_*)"
} False Positives
- ⚠ Unknown
Field Validations
Loading…
Comments (0)
Loading comments...