SigmaHQ / sigma

Main Sigma Rule Repository
Other
7.84k stars 2.12k forks source link

FP Bad practice GPO #4808

Closed frack113 closed 2 months ago

frack113 commented 2 months ago

Summary of the Pull Request

Add FP when use ps1 or bat in the startup machine GPO

Changelog

fix: Windows Binaries Write Suspicious Extensions - Add new filter for when "bat" or "powershell" scripts are written via GPO to run at startup.

Example Log Event

File created: RuleName: T1165 UtcTime: redacted ProcessGuid: {ea5c891b-3d3b-63c3-9320-000000001500} ProcessId: 9308 Image: C:\Windows\system32\svchost.exe TargetFilename: C:\Windows\System32\GroupPolicy\DataStore\0\sysvol\redacted\Policies\{uuid redacted}\Machine\Scripts\Startup\redacted.bat CreationUtcTime: redacted

File created: RuleName: T1165 UtcTime: redacted ProcessGuid: {ea5c891b-3d3b-63c3-9320-000000001500} ProcessId: 9308 Image: C:\Windows\system32\svchost.exe TargetFilename: C:\Windows\System32\GroupPolicy\DataStore\0\sysvol\redacted\Policies\{uuid redacted}\Machine\Scripts\Startup\redacted.ps1 CreationUtcTime: redacted

Fixed Issues

N/A

SigmaHQ Rule Creation Conventions