Update sysmon_abusing_debug_privilege.yml

Field motifiers added.Filter 3 fixed due to logical error
This commit is contained in:
Semanur Guneysu 2020-10-10 13:19:02 +03:00
parent 357d4bd895
commit 75386e6478

View File

@ -13,26 +13,26 @@ logsource:
category: process_creation
detection:
selection:
ParentImage:
- '*\winlogon.exe'
- '*\services.ex'
- '*\lsass.exe'
- '*\csrss.exe'
- '*\smss.exe'
- '*\wininit.exe'
- '*\spoolsv.exe'
- '*\searchindexer.exe'
ParentImage|endswith:
- '\winlogon.exe'
- '\services.exe'
- '\lsass.exe'
- '\csrss.exe'
- '\smss.exe'
- '\wininit.exe'
- '\spoolsv.exe'
- '\searchindexer.exe'
filter1:
Image:
- '*\powershell.exe'
- '*\cmd.exe'
Image|endswith:
- '\powershell.exe'
- '\cmd.exe'
filter2:
User: 'NT AUTHORITY\\SYSTEM'
filter3:
CommandLine:
- ' *route* '
- ' *ADD* '
condition: selection and filter1 and filter2 and filter3
CommandLine|contains:
- 'route'
- 'ADD'
condition: selection and filter1 and filter2 and not filter3
fields:
- ParentImage
- Image