Merge pull request #1664 from frack113/parentofparent

Move to rules-unsupported as use special enrichment field
This commit is contained in:
Florian Roth 2021-07-09 10:55:22 +02:00 committed by GitHub
commit aa0231e1f8
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
3 changed files with 4 additions and 0 deletions

View File

@ -6,12 +6,14 @@ author: Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community
date: 2020/10/13
references:
- https://image.slidesharecdn.com/kheirkhabarovoffzonefinal-181117201458/95/hunting-for-privilege-escalation-in-windows-environment-50-638.jpg
- https://www.slideshare.net/heirhabarov/hunting-for-privilege-escalation-in-windows-environment
tags:
- attack.privilege_escalation
- attack.t1548.002
logsource:
product: windows
category: process_creation
definition : Works only if Enrich Sysmon events with additional information about process in ParentOfParentImage check enrichment section
detection:
parent_image:
ParentImage|endswith:

View File

@ -12,6 +12,7 @@ date: 2019/06/03
logsource:
category: process_creation
product: windows
definition : Works only if Enrich Sysmon events with additional information about process in ParentIntegrityLevel check enrichment section
detection:
selection:
ParentIntegrityLevel: Medium

View File

@ -15,6 +15,7 @@ modified: 2020/09/01
logsource:
category: process_creation
product: windows
definition : Works only if Enrich Sysmon events with additional information about process in ParentUser check enrichment section
detection:
selection:
ParentUser: