Suspicious Security Product Enumeration


Description

Enumeration of security products may be a precursor to Defense Evasion.

Query · eql

api where
  process.Ext.api.name like "IWbemServices::CreateInstanceEnum*" and process.Ext.token.integrity_level_name != "system" and
  process.Ext.api.parameters.operation == "AntiVirusProduct" and
  process.Ext.api.metadata.client_is_local == true and process.parent.executable != null and user.id != "S-1-5-18" and

  /* ignore process cache enrichment failures */
  process.Ext.api.metadata.client_process_id == null and
  
  /* exclusions */
  not(
   (process.name in ("MpCmdRun.exe", "MsMpEng.exe") and
    process.code_signature.subject_name == "Microsoft Windows Publisher" and process.code_signature.trusted == true and
    process.executable :
           ("?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe",
            "?:\\Program Files\\Microsoft Security Client\\*.exe",
            "?:\\Program Files\\Windows Defender\\*.exe",
            "?:\\Program Files (x86)\\Windows Defender\\*.exe",
            "?:\\Program Files (x86)\\Lenovo\\System Update\\ConfigScheduledTask.exe") and
    process.parent.executable :
           ("?:\\Windows\\System32\\services.exe",
            "?:\\Windows\\System32\\svchost.exe",
            "?:\\Program Files\\Windows Defender\\MpCmdRun.exe",
            "?:\\Program Files\\Common Files\\microsoft shared\\ClickToRun\\OfficeClickToRun.exe")) or

   (process.executable : "\\Device\\HarddiskVolume*\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*\\MpCmdRun.exe" and
    process.parent.executable : "\\Device\\HarddiskVolume*\\Windows\\System32\\svchost.exe") or

   (process.executable :
               ("?:\\Windows\\System32\\MRT.exe",
                "?:\\$WINDOWS.~BT\\Sources\\SetupHost.exe",
                "?:\\Windows\\SysWOW64\\systeminfo.exe",
                "?:\\Windows\\System32\\systeminfo.exe",
                "?:\\Program Files\\Windows Defender\\MpCmdRun.exe",
                "C:\\Program Files\\Windows Defender\\MsMpEng.exe",
                "C:\\Program Files\\Microsoft Visual Studio\\20??\\Professional\\Common?\\IDE\\devenv.exe") and
    process.code_signature.subject_name in ("Microsoft Windows", "Microsoft Corporation") and process.code_signature.trusted == true) or

   (process.executable : ("?:\\$Windows.~??\\Sources\\SetupHost.exe", "?:\\$WINDOWS.~??\\Sources\\mighost.exe") and
    process.code_signature.subject_name == "Microsoft Windows" and process.code_signature.trusted == true) or

   (process.executable : "C:\\Windows\\System32\\svchost.exe" and process.parent.executable : "?:\\Windows\\System32\\services.exe") or

   (process.executable : "C:\\Program Files (x86)\\Ivanti\\EPM Agent\\Inventory\\ldiscn32.exe" and
    process.code_signature.subject_name == "Ivanti, Inc." and process.code_signature.trusted == true) or

   (process.executable : "C:\\Program Files (x86)\\ASUS\\AsusFanControlService\\*\\AsusFanControlService.exe" and
    process.code_signature.subject_name == "ASUSTeK COMPUTER INC." and process.code_signature.trusted == true) or

   (process.executable :
            ("?:\\Program Files\\GLPI-Agent\\perl\\bin\\glpi-agent.exe",
             "?:\\Windows\\SysWOW64\\EasyResume.exe",
             "?:\\Windows\\SysWOW64\\Lenovo\\PowerMgr\\EasyResume.exe") and
    process.parent.executable : "?:\\Windows\\System32\\services.exe") or

   (process.executable : "?:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" and process.Ext.api.parameters.operation == "Win32_DeviceGuard" and
    process.parent.executable like "?:\\Program Files\\Microsoft Cloud Managed Desktop Extension\\CMDExtension\\Microsoft.Management.Services.CloudManagedDesktop.Agent.exe") or

   (process.executable : "?:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" and
    process.parent.executable : "?:\\Windows\\System32\\cmd.exe" and user.id == "S-1-5-18" and
    process.Ext.api.parameters.operation == "Win32_DeviceGuard" and
    process.command_line == "Powershell  \"(Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\\Microsoft\\Windows\\DeviceGuard).SecurityServicesRunning\"") or

   (process.executable : "?:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" and
    process.parent.executable : "?:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" and
    user.id == "S-1-5-18" and process.command_line like "*HexProductState*") or

   (process.command_line : "powershell \"Get-CimInstance -Namespace root/SecurityCenter2 -ClassName AntiVirusProduct\"" and
    process.parent.executable : "C:\\Users\\*\\AppData\\Local\\Programs\\DrSprinto\\DrSprinto.exe") or

   (process.command_line : "\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -Version 5.1 -s -NoLogo -NoProfile" and
    process.parent.executable : "C:\\Windows\\_ScriptingFramework\\Modul\\Engine.exe") or

   (process.name in ("powershell.exe", "pwsh.exe") and process.Ext.api.parameters.operation == "Win32_DeviceGuard") or

   (process.executable : "?:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" and
    process.parent.executable : ("?:\\Windows\\explorer.exe", "?:\\Windows\\System32\\cmd.exe", "?:\\Program Files\\Mesh Agent\\MeshAgent.exe") and
    process.command_line : ("powershell",
                             "C:\\WINDOWS\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
                             "\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" ",
                             "\"C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\powershell.exe\" -noexit -command import-module ActiveDirectory",
                             "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe  \"Get-CimInstance -classname 'Win32_DeviceGuard' -namespace 'root\\Microsoft\\Windows\\DeviceGuard' | select-Object -property 'SecurityServicesRunning' | Out-File 'C:\\Program Files\\SCAP Compliance Checker 5.10.1\\Local\\LOCALHOST_*.tmp'\"",
                             "powershell.exe -NoLogo -NoProfile -command \"try { $VBSStatus=(Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\\Microsoft\\Windows\\DeviceGuard).VirtualizationBasedSecurityStatus; if ($VBSStatus -eq $null) { Write-Output 0 } else { Write-Output $VBSStatus } } catch { Write-Output 0 }\"")) or

   (process.code_signature.subject_name in ("CPUID", "Lakeside Software, LLC", "CYBELSOFT", "Connectwise, LLC",
    "Corsair Memory, Inc.", "Ivanti, Inc.", "POINTWARE INFORMATICA LTDA", "ASUSTeK COMPUTER INC.", "Snow Software AB",
    "IObit CO., LTD", "ESET, spol. s r.o.", "Sophos Ltd", "WithSecure Oyj", "Trend Micro, Inc.", "Belarc, Inc.",
    "KASEYA HOLDINGS INC.", "Elliptic Laboratories ASA", "IObit Information Technology", "CPUID S.A.R.L.U.", "CPUID",
    "Panda Security S.L", "Shenzhen Drive The Life Technology Co.,Ltd.", "PDQ.com Corporation", "KERISH PRODUCTS LLP") and
    process.code_signature.trusted == true) or

    process.executable :
             ("C:\\Program Files (x86)\\Varian\\KeystoneAgent\\VMS.Keystone.DeploymentAgent.exe",
              "C:\\Program Files\\FusionInventory-Agent\\perl\\bin\\perl.exe",
              "C:\\Program Files\\FusionInventory-Agent\\perl\\bin\\fusioninventory-agent.exe",
              "C:\\Program Files (x86)\\Varian\\KeystoneAgent\\VMS.Keystone.DeploymentAgent.exe",
              "C:\\Program Files\\AzureConnectedMachineAgent\\GCArcService2\\GC\\gc_worker.exe",
              "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
              "C:\\Program Files (x86)\\FusionInventory-Agent\\perl\\bin\\fusioninventory-agent.exe",
              "C:\\Windows\\System32\\CompatTelRunner.exe",
              "C:\\Windows\\SysWOW64\\systeminfo.exe",
              "C:\\Windows\\System32\\systeminfo.exe",
              "C:\\Program Files\\Windows Defender\\MpCmdRun.exe",
              "C:\\Program Files (x86)\\Kaseya\\KSAASS*\\AgentMon.exe",
              "C:\\Program Files\\BMC Software\\Client Management\\Client\\bin\\mtxagent.exe",
              "C:\\Program Files (x86)\\LANDesk\\LDClient\\LDISCN32.EXE",
              "C:\\Program Files\\GLPI-Agent\\perl\\bin\\glpi-agent.exe",
              "C:\\Program Files (x86)\\GLPI-Agent\\perl\\bin\\glpi-agent.exe",
              "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*\\MpCmdRun.exe",
              "C:\\Program Files (x86)\\Google\\Chrome\\Application\\*\\elevation_service.exe",
              "C:\\Program Files\\Microsoft Visual Studio\\20??\\Enterprise\\Common?\\IDE\\devenv.exe",
              "C:\\Program Files (x86)\\OSTotoSoft\\DriverTalent\\HardWareReport.exe",
              "C:\\Windows\\System32\\UsoClient.exe",
              "C:\\Windows\\CCM\\CcmExec.exe",
              "C:\\Windows\\system32\\wsmprovhost.exe",
              "\\Device\\Mup\\*.exe",
              "C:\\Windows\\Microsoft.NET\\Framework64\\v4.*\\mscorsvw.exe",
              "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.*\\MpCmdRun.exe",
              "C:\\Program Files\\Microsoft Visual Studio\\*\\Common?\\IDE\\devenv.exe",
              "C:\\Program Files\\Microsoft OneDrive\\*\\FileCoAuth.exe") or

    (process.parent.executable : "?:\\Windows\\System32\\WmiPrvSe.exe" and process.name == "powershell.exe" and
     process.command_line : "\"C:\\WINDOWS\\system32\\WindowsPowerShell\\v1.0\\PowerShell.exe\" -NoLogo -Noninteractive -NoProfile  -ExecutionPolicy Bypass \"& 'C:\\WINDOWS\\CCM\\SystemTemp\\*.ps1'\"") or

    (process.name : "powershell.exe" and
     process.parent.executable : ("C:\\Program Files\\Tychon\\TychonEngine.exe", "C:\\Windows\\System32\\EVENTSENTRY\\eventsentry_svc_x64.exe")) or

    (process.name : "powershell.exe" and
     process.command_line : ("powershell  Get-CimInstance –ClassName Win32_DeviceGuard –Namespace root\\Microsoft\\Windows\\DeviceGuard",
                             "\"C:\\WINDOWS\\system32\\WindowsPowerShell\\v1.0\\PowerShell.exe\" -NoLogo -Noninteractive -NoProfile  -ExecutionPolicy Bypass \"& 'C:\\WINDOWS\\CCM\\SystemTemp\\*.ps1'\" True")) or

    (process.name : "cscript.exe" and process.parent.executable : "C:\\Program Files (x86)\\Bostonpost Technology\\Property Manager *\\propertymanager.exe") or

     (process.name : "powershell.exe" and 
      process.parent.executable : ("C:\\Program Files\\Windows Defender Advanced Threat Protection\\SenseIR.exe",
                                   "C:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\Platform\\*\\SenseIR.exe")) or

    (process.executable : "?:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" and
     process.command_line : "*\\CommandCenterAgent\\agent.ps1*") or

    (process.parent.executable : "?:\\Windows\\System32\\wscript.exe" and
     process.command_line : "*\\CommandCenterAgent\\*")
  )
Raw source Suspicious Security Product Enumeration · Elastic TOML
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[rule]
description = "Enumeration of security products may be a precursor to Defense Evasion."
id = "8749c08b-58f5-4e7c-ab15-3551b7541f7a"
license = "Elastic License v2"
name = "Suspicious Security Product Enumeration"
os_list = ["windows"]
version = "1.0.18"

query = '''
api where
  process.Ext.api.name like "IWbemServices::CreateInstanceEnum*" and process.Ext.token.integrity_level_name != "system" and
  process.Ext.api.parameters.operation == "AntiVirusProduct" and
  process.Ext.api.metadata.client_is_local == true and process.parent.executable != null and user.id != "S-1-5-18" and

  /* ignore process cache enrichment failures */
  process.Ext.api.metadata.client_process_id == null and
  
  /* exclusions */
  not(
   (process.name in ("MpCmdRun.exe", "MsMpEng.exe") and
    process.code_signature.subject_name == "Microsoft Windows Publisher" and process.code_signature.trusted == true and
    process.executable :
           ("?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe",
            "?:\\Program Files\\Microsoft Security Client\\*.exe",
            "?:\\Program Files\\Windows Defender\\*.exe",
            "?:\\Program Files (x86)\\Windows Defender\\*.exe",
            "?:\\Program Files (x86)\\Lenovo\\System Update\\ConfigScheduledTask.exe") and
    process.parent.executable :
           ("?:\\Windows\\System32\\services.exe",
            "?:\\Windows\\System32\\svchost.exe",
            "?:\\Program Files\\Windows Defender\\MpCmdRun.exe",
            "?:\\Program Files\\Common Files\\microsoft shared\\ClickToRun\\OfficeClickToRun.exe")) or

   (process.executable : "\\Device\\HarddiskVolume*\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*\\MpCmdRun.exe" and
    process.parent.executable : "\\Device\\HarddiskVolume*\\Windows\\System32\\svchost.exe") or

   (process.executable :
               ("?:\\Windows\\System32\\MRT.exe",
                "?:\\$WINDOWS.~BT\\Sources\\SetupHost.exe",
                "?:\\Windows\\SysWOW64\\systeminfo.exe",
                "?:\\Windows\\System32\\systeminfo.exe",
                "?:\\Program Files\\Windows Defender\\MpCmdRun.exe",
                "C:\\Program Files\\Windows Defender\\MsMpEng.exe",
                "C:\\Program Files\\Microsoft Visual Studio\\20??\\Professional\\Common?\\IDE\\devenv.exe") and
    process.code_signature.subject_name in ("Microsoft Windows", "Microsoft Corporation") and process.code_signature.trusted == true) or

   (process.executable : ("?:\\$Windows.~??\\Sources\\SetupHost.exe", "?:\\$WINDOWS.~??\\Sources\\mighost.exe") and
    process.code_signature.subject_name == "Microsoft Windows" and process.code_signature.trusted == true) or

   (process.executable : "C:\\Windows\\System32\\svchost.exe" and process.parent.executable : "?:\\Windows\\System32\\services.exe") or

   (process.executable : "C:\\Program Files (x86)\\Ivanti\\EPM Agent\\Inventory\\ldiscn32.exe" and
    process.code_signature.subject_name == "Ivanti, Inc." and process.code_signature.trusted == true) or

   (process.executable : "C:\\Program Files (x86)\\ASUS\\AsusFanControlService\\*\\AsusFanControlService.exe" and
    process.code_signature.subject_name == "ASUSTeK COMPUTER INC." and process.code_signature.trusted == true) or

   (process.executable :
            ("?:\\Program Files\\GLPI-Agent\\perl\\bin\\glpi-agent.exe",
             "?:\\Windows\\SysWOW64\\EasyResume.exe",
             "?:\\Windows\\SysWOW64\\Lenovo\\PowerMgr\\EasyResume.exe") and
    process.parent.executable : "?:\\Windows\\System32\\services.exe") or

   (process.executable : "?:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" and process.Ext.api.parameters.operation == "Win32_DeviceGuard" and
    process.parent.executable like "?:\\Program Files\\Microsoft Cloud Managed Desktop Extension\\CMDExtension\\Microsoft.Management.Services.CloudManagedDesktop.Agent.exe") or

   (process.executable : "?:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" and
    process.parent.executable : "?:\\Windows\\System32\\cmd.exe" and user.id == "S-1-5-18" and
    process.Ext.api.parameters.operation == "Win32_DeviceGuard" and
    process.command_line == "Powershell  \"(Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\\Microsoft\\Windows\\DeviceGuard).SecurityServicesRunning\"") or

   (process.executable : "?:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" and
    process.parent.executable : "?:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" and
    user.id == "S-1-5-18" and process.command_line like "*HexProductState*") or

   (process.command_line : "powershell \"Get-CimInstance -Namespace root/SecurityCenter2 -ClassName AntiVirusProduct\"" and
    process.parent.executable : "C:\\Users\\*\\AppData\\Local\\Programs\\DrSprinto\\DrSprinto.exe") or

   (process.command_line : "\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -Version 5.1 -s -NoLogo -NoProfile" and
    process.parent.executable : "C:\\Windows\\_ScriptingFramework\\Modul\\Engine.exe") or

   (process.name in ("powershell.exe", "pwsh.exe") and process.Ext.api.parameters.operation == "Win32_DeviceGuard") or

   (process.executable : "?:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" and
    process.parent.executable : ("?:\\Windows\\explorer.exe", "?:\\Windows\\System32\\cmd.exe", "?:\\Program Files\\Mesh Agent\\MeshAgent.exe") and
    process.command_line : ("powershell",
                             "C:\\WINDOWS\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
                             "\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" ",
                             "\"C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\powershell.exe\" -noexit -command import-module ActiveDirectory",
                             "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe  \"Get-CimInstance -classname 'Win32_DeviceGuard' -namespace 'root\\Microsoft\\Windows\\DeviceGuard' | select-Object -property 'SecurityServicesRunning' | Out-File 'C:\\Program Files\\SCAP Compliance Checker 5.10.1\\Local\\LOCALHOST_*.tmp'\"",
                             "powershell.exe -NoLogo -NoProfile -command \"try { $VBSStatus=(Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\\Microsoft\\Windows\\DeviceGuard).VirtualizationBasedSecurityStatus; if ($VBSStatus -eq $null) { Write-Output 0 } else { Write-Output $VBSStatus } } catch { Write-Output 0 }\"")) or

   (process.code_signature.subject_name in ("CPUID", "Lakeside Software, LLC", "CYBELSOFT", "Connectwise, LLC",
    "Corsair Memory, Inc.", "Ivanti, Inc.", "POINTWARE INFORMATICA LTDA", "ASUSTeK COMPUTER INC.", "Snow Software AB",
    "IObit CO., LTD", "ESET, spol. s r.o.", "Sophos Ltd", "WithSecure Oyj", "Trend Micro, Inc.", "Belarc, Inc.",
    "KASEYA HOLDINGS INC.", "Elliptic Laboratories ASA", "IObit Information Technology", "CPUID S.A.R.L.U.", "CPUID",
    "Panda Security S.L", "Shenzhen Drive The Life Technology Co.,Ltd.", "PDQ.com Corporation", "KERISH PRODUCTS LLP") and
    process.code_signature.trusted == true) or

    process.executable :
             ("C:\\Program Files (x86)\\Varian\\KeystoneAgent\\VMS.Keystone.DeploymentAgent.exe",
              "C:\\Program Files\\FusionInventory-Agent\\perl\\bin\\perl.exe",
              "C:\\Program Files\\FusionInventory-Agent\\perl\\bin\\fusioninventory-agent.exe",
              "C:\\Program Files (x86)\\Varian\\KeystoneAgent\\VMS.Keystone.DeploymentAgent.exe",
              "C:\\Program Files\\AzureConnectedMachineAgent\\GCArcService2\\GC\\gc_worker.exe",
              "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
              "C:\\Program Files (x86)\\FusionInventory-Agent\\perl\\bin\\fusioninventory-agent.exe",
              "C:\\Windows\\System32\\CompatTelRunner.exe",
              "C:\\Windows\\SysWOW64\\systeminfo.exe",
              "C:\\Windows\\System32\\systeminfo.exe",
              "C:\\Program Files\\Windows Defender\\MpCmdRun.exe",
              "C:\\Program Files (x86)\\Kaseya\\KSAASS*\\AgentMon.exe",
              "C:\\Program Files\\BMC Software\\Client Management\\Client\\bin\\mtxagent.exe",
              "C:\\Program Files (x86)\\LANDesk\\LDClient\\LDISCN32.EXE",
              "C:\\Program Files\\GLPI-Agent\\perl\\bin\\glpi-agent.exe",
              "C:\\Program Files (x86)\\GLPI-Agent\\perl\\bin\\glpi-agent.exe",
              "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*\\MpCmdRun.exe",
              "C:\\Program Files (x86)\\Google\\Chrome\\Application\\*\\elevation_service.exe",
              "C:\\Program Files\\Microsoft Visual Studio\\20??\\Enterprise\\Common?\\IDE\\devenv.exe",
              "C:\\Program Files (x86)\\OSTotoSoft\\DriverTalent\\HardWareReport.exe",
              "C:\\Windows\\System32\\UsoClient.exe",
              "C:\\Windows\\CCM\\CcmExec.exe",
              "C:\\Windows\\system32\\wsmprovhost.exe",
              "\\Device\\Mup\\*.exe",
              "C:\\Windows\\Microsoft.NET\\Framework64\\v4.*\\mscorsvw.exe",
              "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.*\\MpCmdRun.exe",
              "C:\\Program Files\\Microsoft Visual Studio\\*\\Common?\\IDE\\devenv.exe",
              "C:\\Program Files\\Microsoft OneDrive\\*\\FileCoAuth.exe") or

    (process.parent.executable : "?:\\Windows\\System32\\WmiPrvSe.exe" and process.name == "powershell.exe" and
     process.command_line : "\"C:\\WINDOWS\\system32\\WindowsPowerShell\\v1.0\\PowerShell.exe\" -NoLogo -Noninteractive -NoProfile  -ExecutionPolicy Bypass \"& 'C:\\WINDOWS\\CCM\\SystemTemp\\*.ps1'\"") or

    (process.name : "powershell.exe" and
     process.parent.executable : ("C:\\Program Files\\Tychon\\TychonEngine.exe", "C:\\Windows\\System32\\EVENTSENTRY\\eventsentry_svc_x64.exe")) or

    (process.name : "powershell.exe" and
     process.command_line : ("powershell  Get-CimInstance –ClassName Win32_DeviceGuard –Namespace root\\Microsoft\\Windows\\DeviceGuard",
                             "\"C:\\WINDOWS\\system32\\WindowsPowerShell\\v1.0\\PowerShell.exe\" -NoLogo -Noninteractive -NoProfile  -ExecutionPolicy Bypass \"& 'C:\\WINDOWS\\CCM\\SystemTemp\\*.ps1'\" True")) or

    (process.name : "cscript.exe" and process.parent.executable : "C:\\Program Files (x86)\\Bostonpost Technology\\Property Manager *\\propertymanager.exe") or

     (process.name : "powershell.exe" and 
      process.parent.executable : ("C:\\Program Files\\Windows Defender Advanced Threat Protection\\SenseIR.exe",
                                   "C:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\Platform\\*\\SenseIR.exe")) or

    (process.executable : "?:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" and
     process.command_line : "*\\CommandCenterAgent\\agent.ps1*") or

    (process.parent.executable : "?:\\Windows\\System32\\wscript.exe" and
     process.command_line : "*\\CommandCenterAgent\\*")
  )
'''

min_endpoint_version = "8.15.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1518"
name = "Software Discovery"
reference = "https://attack.mitre.org/techniques/T1518/"
[[threat.technique.subtechnique]]
id = "T1518.001"
name = "Security Software Discovery"
reference = "https://attack.mitre.org/techniques/T1518/001/"



[threat.tactic]
id = "TA0007"
name = "Discovery"
reference = "https://attack.mitre.org/tactics/TA0007/"

[internal]
min_endpoint_version = "8.15.0"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.