2020-03-04 19:57:41 +00:00
title : MMC20 Lateral Movement
id : f1f3bf22-deb2-418d-8cce-e1a45e46a5bd
2020-06-16 20:46:08 +00:00
description : Detects MMC20.Application Lateral Movement; specifically looks for the spawning of the parent MMC.exe with a command line of "-Embedding" as a child of svchost.exe
2020-08-24 23:09:17 +00:00
author : '@2xxeformyshirt (Security Risk Advisors) - rule; Teymur Kheirkhabarov (idea)'
2020-03-04 19:57:41 +00:00
date : 2020 /03/04
2020-08-24 23:09:17 +00:00
modified : 2020 /08/23
2020-03-04 19:57:41 +00:00
references :
2020-06-16 20:46:08 +00:00
- https://enigma0x3.net/2017/01/05/lateral-movement-using-the-mmc20-application-com-object/
- https://drive.google.com/file/d/1lKya3_mLnR3UQuCoiYruO3qgu052_iS_/view?usp=sharing
2020-03-04 19:57:41 +00:00
tags :
2020-06-16 20:46:08 +00:00
- attack.execution
2020-08-24 23:09:17 +00:00
- attack.t1175 # an old one
2020-06-16 20:46:08 +00:00
- attack.t1021.003
2020-03-04 19:57:41 +00:00
logsource :
2020-06-16 20:46:08 +00:00
category : process_creation
product : windows
2020-03-04 19:57:41 +00:00
detection :
2020-06-16 20:46:08 +00:00
selection :
ParentImage : '*\svchost.exe'
Image : '*\mmc.exe'
CommandLine : '*-Embedding*'
condition : selection
2020-03-04 19:57:41 +00:00
falsepositives :
2020-06-16 20:46:08 +00:00
- Unlikely
2020-03-04 19:57:41 +00:00
level : high