| ID | Technique | Tactic |
|---|---|---|
| T1055.002 | Portable Executable Injection | Privilege Escalation |
Detection: Windows Process Injection into Commonly Abused Processes
Description
The following analytic detects potential process injection attempts into executables that are commonly abused leveraging Sysmon EventCode 10. It identifies Access Mask requests (0x40 and 0x1fffff) to processes such as notepad.exe, wordpad.exe and calc.exe, excluding common system paths like System32, Syswow64, and Program Files. This activity was associated with the SliverC2 framework by BishopFox. Monitoring this activity may indicate an initial payload attempting to execute malicious code.
Search
1`sysmon`
2EventCode=10
3TargetImage IN (
4 "*\\backgroundtaskhost.exe",
5 "*\\calc.exe",
6 "*\\CalculatorApp.exe",
7 "*\\dllhost.exe",
8 "*\\mspaint.exe",
9 "*\\notepad.exe",
10 "*\\regsvr32.exe",
11 "*\\searchprotocolhost.exe",
12 "*\\spoolsv.exe",
13 "*\\svchost.exe",
14 "*\\werfault.exe",
15 "*\\win32calc.exe",
16 "*\\wordpad.exe",
17 "*\\wuauclt.exe"
18)
19
20NOT SourceImage IN (
21 "*:\\Windows\\Program Files (x86)\\*",
22 "*:\\Windows\\Program Files\\*",
23 "*:\\Windows\\System32\\*",
24 "*:\\Windows\\SysWOW64\\*"
25)
Convert GrantedAccess from hexadecimal to decimal. The original access values represent PROCESS_DUP_HANDLE, modern full process access, and legacy full process access.
1
2| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)
3
4| eval PROCESS_DUP_HANDLE = 64
5
6| eval PROCESS_ALL_ACCESS = 2097151
7
8| eval PROCESS_ALL_ACCESS_LEGACY = 2047999
9
10| eval duplicate_handle_set = bit_and(g_access_decimal, PROCESS_DUP_HANDLE)
11
12| eval full_access_set = bit_and(g_access_decimal, PROCESS_ALL_ACCESS)
13
14| eval legacy_full_access_set = bit_and(g_access_decimal, PROCESS_ALL_ACCESS_LEGACY)
15
16| where duplicate_handle_set == PROCESS_DUP_HANDLE
17 OR full_access_set == PROCESS_ALL_ACCESS
18 OR legacy_full_access_set == PROCESS_ALL_ACCESS_LEGACY
19
20
21| stats count min(_time) as firstTime
22 max(_time) as lastTime
23 BY user_id dest
24 signature_id signature granted_access Opcode
25 SourceImage SourceProcessGUID SourceProcessId
26 TargetImage TargetProcessGUID TargetProcessId
27 CallTrace vendor_product
28
29
30| eval CallTrace=split(CallTrace, "
31|")
32
33
34| `security_content_ctime(firstTime)`
35
36| `security_content_ctime(lastTime)`
37
38| `windows_process_injection_into_commonly_abused_processes_filter`
Data Source
| Name | Platform | Sourcetype | Source |
|---|---|---|---|
| Sysmon EventID 10 | 'XmlWinEventLog' |
'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational' |
Macros Used
| Name | Value |
|---|---|
| sysmon | (source=WinEventLog:Microsoft-Windows-Sysmon/Operational OR source=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR source=Syslog:Linux-Sysmon/Operational) |
| windows_process_injection_into_commonly_abused_processes_filter | search * |
windows_process_injection_into_commonly_abused_processes_filter is an empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
Annotations
Default Configuration
This detection is configured by default in Splunk Enterprise Security to run with the following settings:
| Setting | Value |
|---|---|
| Disabled | true |
| Cron Schedule | 0 * * * * |
| Earliest Time | -70m@m |
| Latest Time | -10m@m |
| Schedule Window | auto |
| Creates Finding (Notable) | No |
| Creates Intermediate Finding (Risk Event) | Yes |
Implementation
To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
Known False Positives
False positives may be present based on SourceImage paths, particularly those with a legitimate reason for accessing lsass.exe or regsvr32.exe. If removing the paths is important, realize svchost and many native binaries inject into processes consistently. Restrict or tune as needed.
Associated Analytic Story
Intermediate Findings
| Message | Entity Field | Entity Type | Risk Score |
|---|---|---|---|
| The process [$SourceImage$] requested a potentially malicious process injection related access mask [$granted_access$] to [$TargetImage$] on [$dest$]. | dest | system | 20 |
Threat Objects
| Field | Type |
|---|---|
| SourceImage | file_path |
References
-
https://dominicbreuker.com/post/learning_sliver_c2_08_implant_basics/
-
https://redcanary.com/threat-detection-report/techniques/process-injection/
-
https://www.cybereason.com/blog/sliver-c2-leveraged-by-many-threat-actors
Detection Testing
| Test Type | Status | Dataset | Source | Sourcetype |
|---|---|---|---|---|
| Validation | ✅ Passing | N/A | N/A | N/A |
| Unit | ✅ Passing | Dataset | XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
XmlWinEventLog |
| Integration | ✅ Passing | Dataset | XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
XmlWinEventLog |
Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI.
Alternatively you can replay a dataset into a Splunk Attack Range
Source: GitHub |
Version: 9