Sticky Key Like Backdoor Execution
Description
Detects the usage and installation of a backdoor that uses an option to register a malicious debugger for built-in tools that are accessible in the login screen
Query · sigma
selection: ParentImage|endswith: \winlogon.exe Image|endswith: - \cmd.exe - \cscript.exe - \mshta.exe - \powershell.exe - \pwsh.exe - \regsvr32.exe - \rundll32.exe - \wscript.exe - \wt.exe CommandLine|contains: - sethc.exe - utilman.exe - osk.exe - Magnify.exe - Narrator.exe - DisplaySwitch.exe condition: selection
Known false positives
- Unlikely