/
proc_creation_win_schtasks_env_folder.yml
73 lines (73 loc) · 2.68 KB
/
proc_creation_win_schtasks_env_folder.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
title: Suspicious Schtasks From Env Var Folder
id: 81325ce1-be01-4250-944f-b4789644556f
related:
- id: 43f487f0-755f-4c2a-bce7-d6d2eec2fcf8 # TODO: Recreate after baseline
type: derived
status: experimental
description: Detects Schtask creations that point to a suspicious folder or an environment variable often used by malware
references:
- https://www.welivesecurity.com/2022/01/18/donot-go-do-not-respawn/
- https://www.joesandbox.com/analysis/514608/0/html#324415FF7D8324231381BAD48A052F85DF04
author: Florian Roth (Nextron Systems)
date: 2022/02/21
modified: 2023/11/30
tags:
- attack.execution
- attack.t1053.005
logsource:
product: windows
category: process_creation
detection:
selection1_create:
Image|endswith: '\schtasks.exe'
CommandLine|contains: ' /create '
selection1_all_folders:
CommandLine|contains:
- ':\Perflogs'
- ':\Windows\Temp'
- '\AppData\Local\'
- '\AppData\Roaming\'
- '\Users\Public'
- '%AppData%'
- '%Public%'
selection2_parent:
ParentCommandLine|endswith: '\svchost.exe -k netsvcs -p -s Schedule'
selection2_some_folders:
CommandLine|contains:
- ':\Perflogs'
- ':\Windows\Temp'
- '\Users\Public'
- '%Public%'
filter_mixed:
- CommandLine|contains:
- 'update_task.xml'
- '/Create /TN TVInstallRestore /TR'
- ParentCommandLine|contains: 'unattended.ini'
filter_avira_install:
# Comment out this filter if you dont use AVIRA
CommandLine|contains|all:
- '/Create /Xml "C:\Users\'
- '\AppData\Local\Temp\.CR.'
- 'Avira_Security_Installation.xml'
filter_avira_other:
# Comment out this filter if you dont use AVIRA
CommandLine|contains|all:
- '/Create /F /TN'
- '/Xml '
- '\AppData\Local\Temp\is-'
- 'Avira_'
CommandLine|contains:
- '.tmp\UpdateFallbackTask.xml'
- '.tmp\WatchdogServiceControlManagerTimeout.xml'
- '.tmp\SystrayAutostart.xml'
- '.tmp\MaintenanceTask.xml'
filter_klite_codec:
CommandLine|contains|all:
- '\AppData\Local\Temp\'
- '/Create /TN "klcp_update" /XML '
- '\klcp_update_task.xml'
condition: ( all of selection1* or all of selection2* ) and not 1 of filter*
falsepositives:
- Benign scheduled tasks creations or executions that happen often during software installations
- Software that uses the AppData folder and scheduled tasks to update the software in the AppData folders
level: medium