Renamed PingCastle Binary Execution
Description
Detects the execution of a renamed "PingCastle" binary based on the PE metadata fields.
Query · sigma
selection: - OriginalFileName: - PingCastleReporting.exe - PingCastleCloud.exe - PingCastle.exe - CommandLine|contains: - --scanner aclcheck - --scanner antivirus - --scanner computerversion - --scanner foreignusers - --scanner laps_bitlocker - --scanner localadmin - --scanner nullsession - --scanner nullsession-trust - --scanner oxidbindings - --scanner remote - --scanner share - --scanner smb - --scanner smb3querynetwork - --scanner spooler - --scanner startup - --scanner zerologon - CommandLine|contains: --no-enum-limit - CommandLine|contains|all: - --healthcheck - --level Full - CommandLine|contains|all: - --healthcheck - '--server ' filter_main_img: Image|endswith: - \PingCastleReporting.exe - \PingCastleCloud.exe - \PingCastle.exe condition: selection and not 1 of filter_main_*
Known false positives
- Unknown