Techniques
Sample rules
Windows Process Injection into Commonly Abused Processes
- source: splunk
- technicques:
Description
The following analytic detects potential process injection attempts into executables that are commonly abused leveraging Sysmon EventCode 10. It identifies Access Mask requests (0x40 and 0x1fffff) to processes such as notepad.exe, wordpad.exe and calc.exe, excluding common system paths like System32, Syswow64, and Program Files. This activity was associated with the SliverC2 framework by BishopFox. Monitoring this activity may indicate an initial payload attempting to execute malicious code.
Detection logic
`sysmon`
EventCode=10
TargetImage IN (
"*\\backgroundtaskhost.exe",
"*\\calc.exe",
"*\\CalculatorApp.exe",
"*\\dllhost.exe",
"*\\mspaint.exe",
"*\\notepad.exe",
"*\\regsvr32.exe",
"*\\searchprotocolhost.exe",
"*\\spoolsv.exe",
"*\\svchost.exe",
"*\\werfault.exe",
"*\\win32calc.exe",
"*\\wordpad.exe",
"*\\wuauclt.exe"
)
NOT SourceImage IN (
"*:\\Windows\\Program Files (x86)\\*",
"*:\\Windows\\Program Files\\*",
"*:\\Windows\\System32\\*",
"*:\\Windows\\SysWOW64\\*"
)
Convert GrantedAccess from hexadecimal to decimal. The original access values represent PROCESS_DUP_HANDLE, modern full process access, and legacy full process access.
| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)
| eval PROCESS_DUP_HANDLE = 64
| eval PROCESS_ALL_ACCESS = 2097151
| eval PROCESS_ALL_ACCESS_LEGACY = 2047999
| eval duplicate_handle_set = bit_and(g_access_decimal, PROCESS_DUP_HANDLE)
| eval full_access_set = bit_and(g_access_decimal, PROCESS_ALL_ACCESS)
| eval legacy_full_access_set = bit_and(g_access_decimal, PROCESS_ALL_ACCESS_LEGACY)
| where duplicate_handle_set == PROCESS_DUP_HANDLE
OR full_access_set == PROCESS_ALL_ACCESS
OR legacy_full_access_set == PROCESS_ALL_ACCESS_LEGACY
| stats count min(_time) as firstTime
max(_time) as lastTime
BY user_id dest
signature_id signature granted_access Opcode
SourceImage SourceProcessGUID SourceProcessId
TargetImage TargetProcessGUID TargetProcessId
CallTrace vendor_product
| eval CallTrace=split(CallTrace, "
|")
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_process_injection_into_commonly_abused_processes_filter`