LoFP LoFP / it is possible legitimate applications will request access to winlogon, filter as needed.

Techniques

Sample rules

Windows Access Token Manipulation Winlogon Duplicate Token Handle

Description

The following analytic detects a process requesting duplicate-handle and query-limited-information access to winlogon.exe. It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000).

Detection logic

`sysmon`
EventCode=10
TargetImage="*:\\Windows\\system32\\winlogon.exe"

NOT SourceImage IN (
    "C:\\Windows\\system32\\LogonUI.exe",
    "C:\\Windows\\system32\\lsass.exe",
    "C:\\Windows\\system32\\smss.exe",
    "C:\\Windows\\system32\\svchost.exe",
    "C:\\Windows\\system32\\wbem\\wmiprvse.exe"
)

Convert GrantedAccess from hexadecimal to decimal. 0x1040 combines PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000).


| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)

| eval PROCESS_DUP_HANDLE = 64

| eval PROCESS_QUERY_LIMITED_INFORMATION = 4096

| eval duplicate_handle_set = bit_and(g_access_decimal, PROCESS_DUP_HANDLE)

| eval query_limited_set = bit_and(g_access_decimal, PROCESS_QUERY_LIMITED_INFORMATION)

| where duplicate_handle_set == PROCESS_DUP_HANDLE
  AND query_limited_set == PROCESS_QUERY_LIMITED_INFORMATION


| stats count min(_time) as firstTime
                max(_time) as lastTime
    BY user_id dest
       signature_id signature granted_access Opcode
       SourceImage SourceProcessGUID SourceProcessId
       TargetImage TargetProcessGUID TargetProcessId
       CallTrace vendor_product


| eval CallTrace=split(CallTrace, "
|")


| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `windows_access_token_manipulation_winlogon_duplicate_token_handle_filter`

Windows Access Token Winlogon Duplicate Handle In Uncommon Path

Description

The following analytic detects duplicate-handle and query-limited-information access to winlogon.exe from an uncommon or public source path. It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000).

Detection logic

`sysmon`
EventCode=10
TargetImage="*:\\Windows\\System32\\winlogon.exe"
NOT SourceImage IN (
    "%SystemRoot%\\*",
    "C:\\Program Files (x86)\\*",
    "C:\\Program Files\\*",
    "C:\\Windows\\*"
)

Convert GrantedAccess from hexadecimal to decimal. 0x1040 combines PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000).


| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)

| eval PROCESS_DUP_HANDLE = 64

| eval PROCESS_QUERY_LIMITED_INFORMATION = 4096

| eval duplicate_handle_set = bit_and(g_access_decimal, PROCESS_DUP_HANDLE)

| eval query_limited_set = bit_and(g_access_decimal, PROCESS_QUERY_LIMITED_INFORMATION)

| where duplicate_handle_set == PROCESS_DUP_HANDLE
  AND query_limited_set == PROCESS_QUERY_LIMITED_INFORMATION


| stats count min(_time) as firstTime
                max(_time) as lastTime
    BY user_id dest
       signature_id signature granted_access Opcode
       SourceImage SourceProcessGUID SourceProcessId
       TargetImage TargetProcessGUID TargetProcessId
       CallTrace vendor_product


| eval CallTrace=split(CallTrace, "
|")


| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `windows_access_token_winlogon_duplicate_handle_in_uncommon_path_filter`