Detection: Windows Process Injection into Commonly Abused Processes

Description

The following analytic detects potential process injection attempts into executables that are commonly abused leveraging Sysmon EventCode 10. It identifies Access Mask requests (0x40 and 0x1fffff) to processes such as notepad.exe, wordpad.exe and calc.exe, excluding common system paths like System32, Syswow64, and Program Files. This activity was associated with the SliverC2 framework by BishopFox. Monitoring this activity may indicate an initial payload attempting to execute malicious code.

 1`sysmon`
 2EventCode=10
 3TargetImage IN (
 4    "*\\backgroundtaskhost.exe",
 5    "*\\calc.exe",
 6    "*\\CalculatorApp.exe",
 7    "*\\dllhost.exe",
 8    "*\\mspaint.exe",
 9    "*\\notepad.exe",
10    "*\\regsvr32.exe",
11    "*\\searchprotocolhost.exe",
12    "*\\spoolsv.exe",
13    "*\\svchost.exe",
14    "*\\werfault.exe",
15    "*\\win32calc.exe",
16    "*\\wordpad.exe",
17    "*\\wuauclt.exe"
18)
19
20NOT SourceImage IN (
21    "*:\\Windows\\Program Files (x86)\\*",
22    "*:\\Windows\\Program Files\\*",
23    "*:\\Windows\\System32\\*",
24    "*:\\Windows\\SysWOW64\\*"
25)

Convert GrantedAccess from hexadecimal to decimal. The original access values represent PROCESS_DUP_HANDLE, modern full process access, and legacy full process access.

 1
 2| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)
 3
 4| eval PROCESS_DUP_HANDLE = 64
 5
 6| eval PROCESS_ALL_ACCESS = 2097151
 7
 8| eval PROCESS_ALL_ACCESS_LEGACY = 2047999
 9
10| eval duplicate_handle_set = bit_and(g_access_decimal, PROCESS_DUP_HANDLE)
11
12| eval full_access_set = bit_and(g_access_decimal, PROCESS_ALL_ACCESS)
13
14| eval legacy_full_access_set = bit_and(g_access_decimal, PROCESS_ALL_ACCESS_LEGACY)
15
16| where duplicate_handle_set == PROCESS_DUP_HANDLE
17  OR full_access_set == PROCESS_ALL_ACCESS
18  OR legacy_full_access_set == PROCESS_ALL_ACCESS_LEGACY
19
20
21| stats count min(_time) as firstTime
22                max(_time) as lastTime
23    BY user_id dest
24       signature_id signature granted_access Opcode
25       SourceImage SourceProcessGUID SourceProcessId
26       TargetImage TargetProcessGUID TargetProcessId
27       CallTrace vendor_product
28
29
30| eval CallTrace=split(CallTrace, "
31|")
32
33
34| `security_content_ctime(firstTime)`
35
36| `security_content_ctime(lastTime)`
37
38| `windows_process_injection_into_commonly_abused_processes_filter`

Data Source

Name Platform Sourcetype Source
Sysmon EventID 10 Windows icon Windows 'XmlWinEventLog' 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'

Macros Used

Name Value
sysmon (source=WinEventLog:Microsoft-Windows-Sysmon/Operational OR source=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR source=Syslog:Linux-Sysmon/Operational)
windows_process_injection_into_commonly_abused_processes_filter search *
windows_process_injection_into_commonly_abused_processes_filter is an empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.

Annotations

- MITRE ATT&CK
+ Kill Chain Phases
+ NIST
+ CIS
- Threat Actors
ID Technique Tactic
T1055.002 Portable Executable Injection Privilege Escalation
Exploitation
DE.AE
CIS 10

Default Configuration

This detection is configured by default in Splunk Enterprise Security to run with the following settings:

Setting Value
Disabled true
Cron Schedule 0 * * * *
Earliest Time -70m@m
Latest Time -10m@m
Schedule Window auto
Creates Finding (Notable) No
Creates Intermediate Finding (Risk Event) Yes
Anomaly detections generate Intermediate Findings (Risk Events). They do not generate a Finding (Notable) directly.

Implementation

To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.

Known False Positives

False positives may be present based on SourceImage paths, particularly those with a legitimate reason for accessing lsass.exe or regsvr32.exe. If removing the paths is important, realize svchost and many native binaries inject into processes consistently. Restrict or tune as needed.

Associated Analytic Story

Intermediate Findings

Message Entity Field Entity Type Risk Score
The process [$SourceImage$] requested a potentially malicious process injection related access mask [$granted_access$] to [$TargetImage$] on [$dest$]. dest system 20

Threat Objects

Field Type
SourceImage file_path

References

Detection Testing

Test Type Status Dataset Source Sourcetype
Validation ✅ Passing N/A N/A N/A
Unit ✅ Passing Dataset XmlWinEventLog:Microsoft-Windows-Sysmon/Operational XmlWinEventLog
Integration ✅ Passing Dataset XmlWinEventLog:Microsoft-Windows-Sysmon/Operational XmlWinEventLog

Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI. Alternatively you can replay a dataset into a Splunk Attack Range


Source: GitHub |

Version: 9