title: IIS Native-Code Module Command Line Installation description: Detects suspicious IIS native-code module installations via command line status: experimental references: - https://researchcenter.paloaltonetworks.com/2018/01/unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east/ author: Florian Roth modified: 2012/12/11 tags: - attack.persistence - attack.t1100 logsource: category: process_creation product: windows detection: selection: CommandLine: - '*\APPCMD.EXE install module /name:*' condition: selection falsepositives: - Unknown as it may vary from organisation to arganisation how admins use to install IIS modules level: medium