Suspicious SYSTEM User Process Creation
Description
Detects a suspicious process creation as SYSTEM user (suspicious program or command line parameter)
Query · sigma
selection: IntegrityLevel: - System - S-1-16-16384 User|contains: - AUTHORI - AUTORI selection_special: - Image|endswith: - \calc.exe - \cscript.exe - \forfiles.exe - \hh.exe - \mshta.exe - \ping.exe - \wscript.exe - CommandLine|re: net\s+user\s+ - CommandLine|contains: - ' -NoP ' - ' -W Hidden ' - ' -decode ' - ' /decode ' - ' /urlcache ' - ' -urlcache ' - ' -e* JAB' - ' -e* SUVYI' - ' -e* SQBFAFgA' - ' -e* aWV4I' - ' -e* IAB' - ' -e* PAA' - ' -e* aQBlAHgA' - vssadmin delete shadows - reg SAVE HKLM - ' -ma ' - Microsoft\Windows\CurrentVersion\Run - .downloadstring( - .downloadfile( - ' /ticket:' - 'dpapi::' - event::clear - event::drop - id::modify - 'kerberos::' - 'lsadump::' - 'misc::' - 'privilege::' - 'rpc::' - 'sekurlsa::' - 'sid::' - 'token::' - vault::cred - vault::list - ' p::d ' - ;iex( - MiniDump filter_main_ping: CommandLine|contains|all: - ping - 127.0.0.1 - ' -n ' filter_vs: Image|endswith: \PING.EXE ParentCommandLine|contains: \DismFoDInstall.cmd filter_config_mgr: ParentImage|contains: :\Packages\Plugins\Microsoft.GuestConfiguration.ConfigurationforWindows\ filter_java: ParentImage|contains: - :\Program Files (x86)\Java\ - :\Program Files\Java\ ParentImage|endswith: \bin\javaws.exe Image|contains: - :\Program Files (x86)\Java\ - :\Program Files\Java\ Image|endswith: \bin\jp2launcher.exe CommandLine|contains: ' -ma ' condition: all of selection* and not 1 of filter_*
Known false positives
- Administrative activity
- Scripts and administrative tools used in the monitored environment
- Monitoring activity