diff --git a/detections/endpoint/detect_html_help_renamed.yml b/detections/deprecated/detect_html_help_renamed.yml similarity index 89% rename from detections/endpoint/detect_html_help_renamed.yml rename to detections/deprecated/detect_html_help_renamed.yml index e9d228305a9..6a71fb80287 100644 --- a/detections/endpoint/detect_html_help_renamed.yml +++ b/detections/deprecated/detect_html_help_renamed.yml @@ -1,10 +1,10 @@ name: Detect HTML Help Renamed id: 62fed254-513b-460e-953d-79771493a9f3 -version: 14 +version: 15 creation_date: '2021-02-11' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk -status: production +status: deprecated type: Hunting description: The following analytic detects instances where hh.exe (HTML Help) has been renamed and is executing a Compiled HTML Help (CHM) file. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and original file names. This activity is significant because attackers can use renamed hh.exe to execute malicious scripts embedded in CHM files, potentially leading to code execution. If confirmed malicious, this technique could allow attackers to run arbitrary scripts, escalate privileges, or persist within the environment, posing a significant security risk. data_source: @@ -53,3 +53,8 @@ tests: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.10.0 + replacement_content: + - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/endpoint/detect_mshta_renamed.yml b/detections/deprecated/detect_mshta_renamed.yml similarity index 88% rename from detections/endpoint/detect_mshta_renamed.yml rename to detections/deprecated/detect_mshta_renamed.yml index e04f4d7434c..a18668a17fe 100644 --- a/detections/endpoint/detect_mshta_renamed.yml +++ b/detections/deprecated/detect_mshta_renamed.yml @@ -1,10 +1,10 @@ name: Detect mshta renamed id: 8f45fcf0-5b68-11eb-ae93-0242ac130002 -version: 13 +version: 14 creation_date: '2021-01-15' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk -status: production +status: deprecated type: Hunting description: The following analytic identifies instances where mshta.exe has been renamed and executed. It leverages Endpoint Detection and Response (EDR) data, specifically focusing on the original file name field to detect discrepancies. This activity is significant because renaming mshta.exe is a common tactic used by attackers to evade detection and execute malicious scripts. If confirmed malicious, this could allow an attacker to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further lateral movement within the network. data_source: @@ -52,3 +52,8 @@ tests: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.10.0 + replacement_content: + - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/endpoint/detect_renamed_7_zip.yml b/detections/deprecated/detect_renamed_7_zip.yml similarity index 88% rename from detections/endpoint/detect_renamed_7_zip.yml rename to detections/deprecated/detect_renamed_7_zip.yml index 667a8ad2f50..fea1e5e5ce5 100644 --- a/detections/endpoint/detect_renamed_7_zip.yml +++ b/detections/deprecated/detect_renamed_7_zip.yml @@ -1,10 +1,10 @@ name: Detect Renamed 7-Zip id: 4057291a-b8cf-11eb-95fe-acde48001122 -version: 12 +version: 13 creation_date: '2021-06-03' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk -status: production +status: deprecated type: Hunting description: The following analytic detects the usage of a renamed 7-Zip executable using Sysmon data. It leverages the OriginalFileName field to identify instances where the 7-Zip process has been renamed. This activity is significant as attackers often rename legitimate tools to evade detection while staging or exfiltrating data. If confirmed malicious, this behavior could indicate data exfiltration attempts or other unauthorized data manipulation, potentially leading to significant data breaches or loss of sensitive information. Analysts should validate the legitimacy of the 7-Zip executable and investigate parallel processes for further suspicious activities. data_source: @@ -52,3 +52,8 @@ tests: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.10.0 + replacement_content: + - Windows Renamed Popular 3rd Party Software was Executed diff --git a/detections/endpoint/detect_renamed_psexec.yml b/detections/deprecated/detect_renamed_psexec.yml similarity index 89% rename from detections/endpoint/detect_renamed_psexec.yml rename to detections/deprecated/detect_renamed_psexec.yml index 2e56a883799..52e1bdf8899 100644 --- a/detections/endpoint/detect_renamed_psexec.yml +++ b/detections/deprecated/detect_renamed_psexec.yml @@ -1,10 +1,10 @@ name: Detect Renamed PSExec id: 683e6196-b8e8-11eb-9a79-acde48001122 -version: 17 +version: 18 creation_date: '2021-06-03' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk, Alex Oberkircher, Github Community -status: production +status: deprecated type: Hunting description: The following analytic identifies instances where `PsExec.exe` has been renamed and executed on an endpoint. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and original file names. This activity is significant because renaming `PsExec.exe` is a common tactic to evade detection. If confirmed malicious, this could allow an attacker to execute commands remotely, potentially leading to unauthorized access, lateral movement, or further compromise of the network. data_source: @@ -67,3 +67,8 @@ tests: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all command interpreter binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.10.0 + replacement_content: + - Windows Renamed Command Interpreter was Executed diff --git a/detections/endpoint/detect_renamed_rclone.yml b/detections/deprecated/detect_renamed_rclone.yml similarity index 88% rename from detections/endpoint/detect_renamed_rclone.yml rename to detections/deprecated/detect_renamed_rclone.yml index d7bbfa5d717..7e9bccd3330 100644 --- a/detections/endpoint/detect_renamed_rclone.yml +++ b/detections/deprecated/detect_renamed_rclone.yml @@ -1,10 +1,10 @@ name: Detect Renamed RClone id: 6dca1124-b3ec-11eb-9328-acde48001122 -version: 12 +version: 13 creation_date: '2021-05-13' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk -status: production +status: deprecated type: Hunting description: The following analytic detects the execution of a renamed `rclone.exe` process, which is commonly used for data exfiltration to remote destinations. This detection leverages Endpoint Detection and Response (EDR) telemetry, focusing on process names and original file names that do not match. This activity is significant because ransomware groups often use RClone to exfiltrate sensitive data. If confirmed malicious, this behavior could indicate an ongoing data exfiltration attempt, potentially leading to significant data loss and further compromise of the affected systems. data_source: @@ -56,3 +56,8 @@ tests: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.10.0 + replacement_content: + - Windows Renamed Popular 3rd Party Software was Executed diff --git a/detections/endpoint/detect_renamed_winrar.yml b/detections/deprecated/detect_renamed_winrar.yml similarity index 87% rename from detections/endpoint/detect_renamed_winrar.yml rename to detections/deprecated/detect_renamed_winrar.yml index 5779de2a81b..215d1d0a53e 100644 --- a/detections/endpoint/detect_renamed_winrar.yml +++ b/detections/deprecated/detect_renamed_winrar.yml @@ -1,10 +1,10 @@ name: Detect Renamed WinRAR id: 1b7bfb2c-b8e6-11eb-99ac-acde48001122 -version: 16 +version: 17 creation_date: '2021-06-03' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk -status: production +status: deprecated type: Hunting description: The following analytic identifies instances where `WinRAR.exe` has been renamed and executed. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and original file names within the Endpoint data model. This activity is significant because renaming executables is a common tactic used by attackers to evade detection. If confirmed malicious, this could indicate an attempt to bypass security controls, potentially leading to unauthorized data extraction or further system compromise. data_source: @@ -52,3 +52,8 @@ tests: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.10.0 + replacement_content: + - Windows Renamed Popular 3rd Party Software was Executed diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml b/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml similarity index 89% rename from detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml rename to detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml index 21f34aefa8a..ec137b5b28c 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml @@ -1,10 +1,10 @@ name: Suspicious microsoft workflow compiler rename id: f0db4464-55d9-11eb-ae93-0242ac130002 -version: 14 +version: 15 creation_date: '2021-01-19' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk -status: production +status: deprecated type: Hunting description: The following analytic detects the renaming of microsoft.workflow.compiler.exe, a rarely used executable typically located in C:\Windows\Microsoft.NET\Framework64\v4.0.30319. This detection leverages Endpoint Detection and Response (EDR) data, focusing on process names and original file names. This activity is significant because renaming this executable can indicate an attempt to evade security controls. If confirmed malicious, an attacker could use this renamed executable to execute arbitrary code, potentially leading to privilege escalation or persistent access within the environment. data_source: @@ -56,3 +56,8 @@ tests: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.10.0 + replacement_content: + - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/endpoint/suspicious_msbuild_rename.yml b/detections/deprecated/suspicious_msbuild_rename.yml similarity index 89% rename from detections/endpoint/suspicious_msbuild_rename.yml rename to detections/deprecated/suspicious_msbuild_rename.yml index 7a4091f3103..4fb2bbb641e 100644 --- a/detections/endpoint/suspicious_msbuild_rename.yml +++ b/detections/deprecated/suspicious_msbuild_rename.yml @@ -1,10 +1,10 @@ name: Suspicious MSBuild Rename id: 4006adac-5937-11eb-ae93-0242ac130002 -version: 14 +version: 15 creation_date: '2021-01-15' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk -status: production +status: deprecated type: Hunting description: The following analytic detects the execution of renamed instances of msbuild.exe. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and original file names within the Endpoint data model. This activity is significant because msbuild.exe is a legitimate tool often abused by attackers to execute malicious code while evading detection. If confirmed malicious, this behavior could allow an attacker to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further lateral movement within the network. data_source: @@ -58,3 +58,8 @@ tests: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.10.0 + replacement_content: + - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml b/detections/deprecated/windows_lolbas_executed_as_renamed_file.yml similarity index 95% rename from detections/endpoint/windows_lolbas_executed_as_renamed_file.yml rename to detections/deprecated/windows_lolbas_executed_as_renamed_file.yml index de0367bd262..aa90a9b6bce 100644 --- a/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml +++ b/detections/deprecated/windows_lolbas_executed_as_renamed_file.yml @@ -1,10 +1,10 @@ name: Windows LOLBAS Executed As Renamed File id: fd496996-7d9e-4894-8d40-bb85b6192dc6 -version: 10 +version: 11 creation_date: '2024-05-03' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Steven Dick -status: production +status: deprecated type: TTP description: The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. data_source: @@ -63,3 +63,8 @@ tests: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog test_type: unit +deprecation_info: + reason: Detection deprecated due to renaming of its newer version. + removed_in_version: 6.10.0 + replacement_content: + - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/endpoint/windows_regsvr32_renamed_binary.yml b/detections/deprecated/windows_regsvr32_renamed_binary.yml similarity index 90% rename from detections/endpoint/windows_regsvr32_renamed_binary.yml rename to detections/deprecated/windows_regsvr32_renamed_binary.yml index 883a47c7e4b..4d6940c412e 100644 --- a/detections/endpoint/windows_regsvr32_renamed_binary.yml +++ b/detections/deprecated/windows_regsvr32_renamed_binary.yml @@ -1,10 +1,10 @@ name: Windows Regsvr32 Renamed Binary id: 7349a9e9-3cf6-4171-bb0c-75607a8dcd1a -version: 13 +version: 14 creation_date: '2022-10-27' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Teoderick Contreras, Splunk -status: production +status: deprecated type: TTP description: The following analytic identifies instances where the regsvr32.exe binary has been renamed and executed. This detection leverages Endpoint Detection and Response (EDR) data, specifically focusing on the original filename metadata. Renaming regsvr32.exe is significant as it can be an evasion technique used by attackers to bypass security controls. If confirmed malicious, this activity could allow an attacker to execute arbitrary DLLs, potentially leading to code execution, privilege escalation, or persistence within the environment. data_source: @@ -65,3 +65,8 @@ tests: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.10.0 + replacement_content: + - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/endpoint/windows_renamed_powershell_execution.yml b/detections/deprecated/windows_renamed_powershell_execution.yml similarity index 91% rename from detections/endpoint/windows_renamed_powershell_execution.yml rename to detections/deprecated/windows_renamed_powershell_execution.yml index bade4e80afd..dbb8ef8e183 100644 --- a/detections/endpoint/windows_renamed_powershell_execution.yml +++ b/detections/deprecated/windows_renamed_powershell_execution.yml @@ -1,10 +1,10 @@ name: Windows Renamed Powershell Execution id: c08014de-cc5a-42de-9775-76ecd5b37bbd -version: 8 +version: 9 creation_date: '2022-10-27' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Teoderick Contreras, Nasreddine Bencherchali, Splunk -status: production +status: deprecated type: TTP description: The following analytic identifies instances where the PowerShell executable has been renamed and executed under an alternate filename. This behavior is commonly associated with attempts to evade security controls or bypass logging mechanisms that monitor standard PowerShell usage. While rare in legitimate environments, renamed PowerShell binaries are frequently observed in malicious campaigns leveraging Living-off-the-Land Binaries (LOLBins) and fileless malware techniques. This detection flags executions of PowerShell where the process name does not match the default powershell.exe or pwsh.exe, especially when invoked from unusual paths or accompanied by suspicious command-line arguments. data_source: @@ -49,3 +49,8 @@ tests: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all command interpreter binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.10.0 + replacement_content: + - Windows Renamed Command Interpreter was Executed diff --git a/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml b/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml new file mode 100644 index 00000000000..3e97a3ea439 --- /dev/null +++ b/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml @@ -0,0 +1,109 @@ +name: Windows Renamed Command Interpreter was Executed +id: 6f4611be-076e-4fa8-bc78-466588a71442 +version: 1 +creation_date: '2026-09-23' +modification_date: '2026-09-23' +author: Onur Mustafa Erdogan, Splunk +status: production +type: Anomaly +description: |- + The following analytic identifies a Windows command interpreter process being executed where it's process name does not match it's original file name attribute. + Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. +data_source: + - Sysmon EventID 1 + - CrowdStrike ProcessRollup2 +search: |- + | tstats `security_content_summariesonly` + count min(_time) AS firstTime + max(_time) AS lastTime + + FROM datamodel=Endpoint.Processes WHERE + + NOT Processes.original_file_name IN ("-","unknown") + [ + | inputlookup renamed_windows_command_interpreter_binaries + | rename original_file_name as Processes.original_file_name + | table Processes.original_file_name + ] + NOT [ + | inputlookup renamed_windows_command_interpreter_binaries + | rename original_file_name as Processes.process_name + | table Processes.process_name + ] + + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process + Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id + Processes.parent_process_name Processes.parent_process_path + Processes.process Processes.process_exec Processes.process_guid + Processes.process_hash Processes.process_id Processes.process_integrity_level + Processes.process_name Processes.process_path + Processes.user Processes.user_id Processes.vendor_product + + | `drop_dm_object_name(Processes)` + + | eval original_file_name=lower(original_file_name) + + | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) + | where NOT match(process_name, "(?i)".original_file_name) + + | lookup local=t renamed_windows_command_interpreter_binaries original_file_name OUTPUT description + + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_renamed_command_interpreter_was_executed_filter` +how_to_implement: |- + The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents + are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement + this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, + you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk + Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node + of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and + speed up the data modeling process. +known_false_positives: |- + 3rd party software binaries sharing the same name as Windows command interpreter binaries may trigger false positives. +references: + - https://attack.mitre.org/techniques/T1036/ + - https://attack.mitre.org/techniques/T1036/003/ + - https://attack.mitre.org/techniques/T1059/ + - https://redcanary.com/threat-detection-report/techniques/rename-system-utilities/ +drilldown_searches: + - name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: 7d + latest_offset: "0" +intermediate_findings: + entities: + - field: dest + type: system + score: 20 + message: Command Interpreter [$original_file_name$] was renamed as [$process_path$] and later executed on [$dest$] +threat_objects: + - field: process_path + type: file_path +analytic_story: + - Living Off The Land + - Masquerading - Rename System Utilities + - Suspicious Command-Line Executions + - Windows Defense Evasion Tactics + - Water Gamayun +asset_type: Endpoint +mitre_attack_id: + - T1036.003 + - T1059 +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: endpoint +security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/renamed_command_interpreter/renamed_command_interpreter.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit diff --git a/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml new file mode 100644 index 00000000000..bd4176d22ec --- /dev/null +++ b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml @@ -0,0 +1,114 @@ +name: Windows Renamed LOLBAS Binary was Executed +id: 10c3850e-810d-41b4-a197-2f14d7883579 +version: 1 +creation_date: '2026-09-23' +modification_date: '2026-09-23' +author: Steven Dick, Onur Mustafa Erdogan, Splunk +status: production +type: Anomaly +description: |- + The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute. + Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. + The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. +data_source: + - Sysmon EventID 1 + - CrowdStrike ProcessRollup2 +search: |- + | tstats `security_content_summariesonly` + count min(_time) AS firstTime + max(_time) AS lastTime + + FROM datamodel=Endpoint.Processes WHERE + + NOT Processes.original_file_name IN ("-","unknown") + [ + | inputlookup renamed_lolbas_binaries + | rename original_file_name as Processes.original_file_name + | table Processes.original_file_name + ] + NOT [ + | inputlookup renamed_lolbas_binaries + | rename original_file_name as Processes.process_name + | table Processes.process_name + ] + NOT process_name IN ( + 'excelcnv.exe', + 'installutil64.exe', + 'protoc~1.exe', + 'regwrite.exe', + 'vzshadow.exe' + ) + + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process + Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id + Processes.parent_process_name Processes.parent_process_path + Processes.process Processes.process_exec Processes.process_guid + Processes.process_hash Processes.process_id Processes.process_integrity_level + Processes.process_name Processes.process_path + Processes.user Processes.user_id Processes.vendor_product + + | `drop_dm_object_name(Processes)` + + | eval original_file_name=lower(original_file_name) + + | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) + | where NOT match(process_name, "(?i)".original_file_name) + + | lookup local=t renamed_lolbas_binaries original_file_name OUTPUT description + + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_renamed_lolbas_binary_was_executed_filter` +how_to_implement: |- + The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents + are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement + this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, + you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk + Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node + of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and + speed up the data modeling process. +known_false_positives: |- + 3rd party software binaries sharing the same name as LOLBAS utilities may trigger false positives. +references: + - https://attack.mitre.org/techniques/T1036/ + - https://attack.mitre.org/techniques/T1036/003/ + - https://redcanary.com/threat-detection-report/techniques/rename-system-utilities/ +drilldown_searches: + - name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: 7d + latest_offset: "0" +intermediate_findings: + entities: + - field: dest + type: system + score: 20 + message: LOLBAS utility [$original_file_name$] was renamed as [$process_path$] and later executed on [$dest$] +threat_objects: + - field: process_path + type: file_path +analytic_story: + - Living Off The Land + - Masquerading - Rename System Utilities + - Windows Defense Evasion Tactics + - Water Gamayun +asset_type: Endpoint +mitre_attack_id: + - T1036.003 +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: endpoint +security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/renamed_lolbas_binary/renamed_lolbas_binary.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit diff --git a/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml b/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml new file mode 100644 index 00000000000..374458d818c --- /dev/null +++ b/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml @@ -0,0 +1,107 @@ +name: Windows Renamed Popular 3rd Party Software was Executed +id: cf6713c7-ac6b-4963-83a6-39f24ed10aa8 +version: 1 +creation_date: '2026-09-23' +modification_date: '2026-09-23' +author: Onur Mustafa Erdogan, Splunk +status: production +type: Anomaly +description: |- + The following analytic identifies a popular 3rd party software process being executed where it's process name does not match it's original file name attribute. + Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. +data_source: + - Sysmon EventID 1 + - CrowdStrike ProcessRollup2 +search: |- + | tstats `security_content_summariesonly` + count min(_time) AS firstTime + max(_time) AS lastTime + + FROM datamodel=Endpoint.Processes WHERE + + NOT Processes.original_file_name IN ("-","unknown") + [ + | inputlookup renamed_popular_3rd_party_binaries + | rename original_file_name as Processes.original_file_name + | table Processes.original_file_name + ] + NOT [ + | inputlookup renamed_popular_3rd_party_binaries + | rename original_file_name as Processes.process_name + | table Processes.process_name + ] + + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process + Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id + Processes.parent_process_name Processes.parent_process_path + Processes.process Processes.process_exec Processes.process_guid + Processes.process_hash Processes.process_id Processes.process_integrity_level + Processes.process_name Processes.process_path + Processes.user Processes.user_id Processes.vendor_product + + | `drop_dm_object_name(Processes)` + + | eval original_file_name=lower(original_file_name) + + | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) + | where NOT match(process_name, "(?i)".original_file_name) + + | lookup local=t renamed_popular_3rd_party_binaries original_file_name OUTPUT description + + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_renamed_popular_3rd_party_software_was_executed_filter` +how_to_implement: |- + The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents + are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement + this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, + you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk + Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node + of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and + speed up the data modeling process. +known_false_positives: |- + 3rd party software binaries might have overlapping executable names. +references: + - https://attack.mitre.org/techniques/T1036/ + - https://attack.mitre.org/techniques/T1036/003/ + - https://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/ + - https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware/ +drilldown_searches: + - name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: 7d + latest_offset: "0" +intermediate_findings: + entities: + - field: dest + type: system + score: 20 + message: Windows 3rd Party software [$original_file_name$] was renamed as [$process_path$] and later executed on [$dest$] +threat_objects: + - field: process_path + type: file_path +analytic_story: + - Living Off The Land + - Masquerading - Rename System Utilities + - Windows Defense Evasion Tactics + - Water Gamayun +asset_type: Endpoint +mitre_attack_id: + - T1036.003 +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: endpoint +security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/renamed_3rd_party_software/renamed_3rd_party_software.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit diff --git a/detections/endpoint/windows_renamed_python_binary_was_executed.yml b/detections/endpoint/windows_renamed_python_binary_was_executed.yml new file mode 100644 index 00000000000..71bde2bae79 --- /dev/null +++ b/detections/endpoint/windows_renamed_python_binary_was_executed.yml @@ -0,0 +1,86 @@ +name: Windows Renamed Python Binary was Executed +id: 6735153f-2da0-4eba-a428-288898613837 +version: 1 +creation_date: '2026-09-23' +modification_date: '2026-09-23' +author: Onur Mustafa Erdogan, Splunk +status: production +type: Anomaly +description: |- + The following analytic identifies a Python process being executed where it's process name does not match + it's original file name attribute. Processes that have been renamed and executed may be an indicator that + an adversary is attempting to evade defenses or execute malicious code. +data_source: + - Sysmon EventID 1 + - CrowdStrike ProcessRollup2 +search: |- + | tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime + FROM datamodel=Endpoint.Processes + WHERE + NOT Processes.original_file_name IN ("-","unknown") + NOT Processes.process_name IN ("dwagent.exe", "WinUtils.exe") + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec + Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path + Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id + Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product + | `drop_dm_object_name(Processes)` + | eval original_file_name=lower(original_file_name) + | regex original_file_name="(?i)^(?:py|pyw|python|pythonw|python32|python64|pythonw32|pythonw64|ipyw32|ipyw64|python3|pythonw3|python3\.\w+|pythonw3\.\w+)\.exe$" + | regex process_name="(?i)^(?:py|pyw|pip|pip3|python|pythonw|python32|python64|pythonw32|pythonw64|ipyw32|ipyw64|python3|pythonw3|python3\.\w+|pythonw3\.\w+|pip3\.\w+|idle3\.\w+)\.exe$" + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_renamed_python_binary_was_executed_filter` +how_to_implement: |- + The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents + are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement + this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, + you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk + Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node + of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and + speed up the data modeling process. +known_false_positives: Various Python implementations might have a different executable name, which could trigger false positives. +references: + - https://attack.mitre.org/techniques/T1036/ + - https://attack.mitre.org/techniques/T1036/003/ + - https://attack.mitre.org/techniques/T1059/006/ + - https://www.microsoft.com/en-us/security/blog/2026/02/05/clickfix-variant-crashfix-deploying-python-rat-trojan/ +drilldown_searches: + - name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: 7d + latest_offset: "0" +intermediate_findings: + entities: + - field: dest + type: system + score: 20 + message: Python binary [$original_file_name$] was renamed as [$process_path$] and later executed on [$dest$] +threat_objects: + - field: process_name + type: process_name +analytic_story: + - Living Off The Land + - Masquerading - Rename System Utilities + - Windows Defense Evasion Tactics + - Water Gamayun +asset_type: Endpoint +mitre_attack_id: + - T1036.003 + - T1059.006 +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: endpoint +security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/renamed_python_binary/renamed_python_binary.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit diff --git a/lookups/csv/renamed_lolbas_binaries.csv b/lookups/csv/renamed_lolbas_binaries.csv new file mode 100644 index 00000000000..ba83e577f1f --- /dev/null +++ b/lookups/csv/renamed_lolbas_binaries.csv @@ -0,0 +1,147 @@ +original_file_name,description +acccheckconsole.exe,Verifies UI accessibility requirements +addinutil.exe,.NET Tool used for updating cache files for Microsoft Office Add-Ins. +adplus.exe,Debugging tool included with Windows Debugging Tools +agentexecutor.exe,Intune Management Extension included on Intune Managed Devices +appcert.exe,Windows App Certification Kit command-line tool. +appinstaller.exe,Tool used for installation of AppX/MSIX applications on Windows 10 +appvlp.exe,Application Virtualization Utility Included with Microsoft Office 2016 +aspnet_compiler.exe,ASP.NET Compilation Tool +at.exe,Schedule periodic tasks +atbroker.exe,Helper binary for Assistive Technology (AT) +bitsadmin.exe,Used for managing background intelligent transfer +cdb.exe,Debugging tool included with Windows Debugging Tools. +certoc.exe,Used for installing certificates +certreq.exe,Used for requesting and managing certificates +certutil.exe,Windows binary used for handling certificates +cmdkey.exe,"creates, lists, and deletes stored user names and passwords or credentials." +cmdl32.exe,Microsoft Connection Manager Auto-Download +cmstp.exe,Installs or removes a Connection Manager service profile. +colorcpl.exe,Binary that handles color management +conhost.exe,Console Window host +control.exe,Console Window host +csc.exe,Binary file used by .NET to compile C# code +cscript.exe,Binary used to execute scripts in Windows +csi.exe,Command line interface included with Visual Studio. +curl.exe,Used for transferring data to or from a server; bundled with Windows 10 1803+ and can be used to download or upload files (not in repo lookup - added manually) +customshellhost.exe,A host process that is used by custom shells when using Windows in Kiosk mode. +datasvcutil.exe,DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application. +desktopimgdownldr.exe,Windows binary used to configure lockscreen/desktop image +devicecredentialdeployment.exe,Device Credential Deployment +devinit.exe,Visual Studio 2019 tool +devtoolslauncher.exe,Binary will execute specified binary. Part of VS/VScode installation. +dfsvc.exe,ClickOnce engine in Windows used by .NET +diantz.exe,Binary that package existing files into a cabinet (.cab) file +diskshadow.exe,Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS). +dnscmd.exe,A command-line interface for managing DNS servers +dotnet.exe,dotnet.exe comes with .NET Framework +dsdbutil.exe,Dsdbutil is a command-line tool that is built into Windows Server. It is available if you have the AD LDS server role installed. Can be used as a command line utility to export Active Directory. +dumpminitool.exe,Dump tool part Visual Studio 2022 +dxcap.exe,DirectX diagnostics/debugger included with Visual Studio. +esentutl.exe,Binary for working with Microsoft Joint Engine Technology (JET) database +eventvwr.exe,Displays Windows Event Logs in a GUI window. +excel.exe,Microsoft Office binary +expand.exe,Binary that expands one or more compressed files +extexport.exe,Load a DLL located in the C:\test folder with a specific name. +extrac32.exe,"Extract to ADS, copy or overwrite a file with Extrac32.exe" +findstr.exe,"Write to ADS, discover, or download files with Findstr.exe" +finger.exe,Displays information about a user or users on a specified remote computer that is running the Finger service or daemon +fltmc.exe,Filter Manager Control Program used by Windows +forfiles.exe,Selects and executes a command on a file or set of files. This command is useful for batch processing. +fsi.exe,64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK. +fsianycpu.exe,32/64-bit FSharp (F#) Interpreter included with Visual Studio. +fsutil.exe,File System Utility +ftp.exe,A binary designed for connecting to FTP servers +gfxdownloadwrapper.exe,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path." +gpscript.exe,Used by group policy to process scripts +hh.exe,Binary used for processing chm files in Windows +ie4uinit.exe,Executes commands from a specially prepared ie4uinit.inf file. +iediagcmd.exe,Diagnostics Utility for Internet Explorer +ieexec.exe,The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL. +ilasm.exe,used for compile c# code into dll or exe. +imewdbld.exe,Microsoft IME Open Extended Dictionary Module +infdefaultinstall.exe,Binary used to perform installation based on content inside inf files +installutil.exe,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies +jsc.exe,Binary file used by .NET to compile javascript code to .exe or .dll format +ldifde.exe,"Creates, modifies, and deletes LDAP directory objects." +makecab.exe,Binary to package existing files into a cabinet (.cab) file +manage-bde.wsf,Script for managing BitLocker +mavinject.exe,Used by App-v in Windows +mftrace.exe,Trace log generation tool for Media Foundation Tools. +microsoft.nodejstools.pressanykey.exe,Part of the NodeJS Visual Studio tools. +microsoft.workflow.compiler.exe,A utility included with .NET that is capable of compiling and executing C# or VB.net code. +mmc.exe,Load snap-ins to locally and remotely manage Windows systems +msaccess.exe,Microsoft Office binary +msbuild.exe,Used to compile and execute code +msconfig.exe,"MSConfig is a troubleshooting tool which is used to temporarily disable or re-enable software, device drivers or Windows services that run during startup process to help the user determine the cause of a problem with Windows" +msdeploy.exe,Microsoft tool used to deploy Web Applications. +msdt.exe,Microsoft diagnostics tool +mshta.exe,Used by Windows to execute html applications. (.hta) +msiexec.exe,Used by Windows to execute msi files +msohtmed.exe,Microsoft Office binary +mspub.exe,Microsoft Office binary +netsh.exe,Netsh is a Windows tool used to manipulate network interface settings. +ntdsutil.exe,Command line utility used to export Active Directory. +odbcconf.exe,Used in Windows for managing ODBC connections +offlinescannershell.exe,Windows Defender Offline Shell +pcalua.exe,Program Compatibility Assistant +pcwrun.exe,Program Compatibility Wizard +pktmon.exe,Capture Network Packets on the windows 10 with October 2018 Update or later. +pnputil.exe,Used for installing drivers +powerpnt.exe,Microsoft Office binary +presentationhost.exe,File is used for executing Browser applications +print.exe,Used by Windows to send files to the printer +printbrm.exe,Printer Migration Command-Line Tool +protocolhandler.exe,Microsoft Office binary +provlaunch.exe,Launcher process +psr.exe,"Windows Problem Steps Recorder, used to record screen and clicks." +rasautou.exe,Windows Remote Access Dialer +rdrleakdiag.exe,Microsoft Windows resource leak diagnostic tool +reg.exe,Used to manipulate the registry +regasm.exe,Part of .NET +regedit.exe,Used by Windows to manipulate registry +regini.exe,Used to manipulate the registry +register-cimprovider.exe,Used to register new wmi providers +regsvcs.exe,Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies +regsvr32.exe,Used by Windows to register dlls +replace.exe,Used to replace file with another file +rpcping.exe,Used to verify rpc connection +rundll32.exe,Used by Windows to execute dll files +runexehelper.exe,Launcher process +runonce.exe,Executes a Run Once Task that has been configured in the registry +sc.exe,Used by Windows to manage services +schtasks.exe,Schedule periodic tasks +scriptrunner.exe,Execute binary through proxy binary to evade defensive counter measures +setres.exe,Configures display settings +settingsynchost.exe,Host Process for Setting Synchronization +sqldumper.exe,Debugging utility included with Microsoft SQL. +sqlps.exe,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons." +sqltoolsps.exe,Tool included with Microsoft SQL that loads SQL Server cmdlts. A replacement for sqlps.exe. Successor to sqlps.exe in SQL Server 2016+. +stordiag.exe,Storage diagnostic tool +syncappvpublishingserver.exe,Used by App-v to get App-v server lists +tar.exe,Used by Windows to extract and create archives. +testwindowremoteagent.exe,TestWindowRemoteAgent.exe is the command-line tool to establish RPC +ttdinject.exe,Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe) +tttracer.exe,Used by Windows 1809 and newer to Debug Time Travel +unregmp2.exe,Microsoft Windows Media Player Setup Utility +vbc.exe,Binary file used for compile vbs code +verclsid.exe,Used to verify a COM object before it is instantiated by Windows Explorer +visualuiaverifynative.exe,A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls. +vsdiagnostics.exe,Command-line tool used for performing diagnostics. +vshadow.exe,VShadow is a command-line tool that can be used to create and manage volume shadow copies. +vsiisexelauncher.exe,Binary will execute specified binary. Part of VS/VScode installation. +vsjitdebugger.exe,Just-In-Time (JIT) debugger included with Visual Studio +vsls-agent.exe,Agent for Visual Studio Live Share (Code Collaboration) +vstest.console.exe,VSTest.Console.exe is the command-line tool to run tests +wab.exe,Windows address book manager +wbadmin.exe,Windows Backup Administration utility +wfc.exe,The Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK). +winproj.exe,Microsoft Project Executable +winword.exe,Microsoft Office binary +wlrmdr.exe,Windows Logon Reminder executable +wmic.exe,The WMI command-line (WMIC) utility provides a command-line interface for WMI +workfolders.exe,Work Folders +wscript.exe,Used by Windows to execute scripts +wsreset.exe,Used to reset Windows Store settings according to its manifest file +wuauclt.exe,Windows Update Client +xwizard.exe,Execute custom class that has been added to the registry or download a file with Xwizard.exe diff --git a/lookups/csv/renamed_lolbas_binaries.yml b/lookups/csv/renamed_lolbas_binaries.yml new file mode 100644 index 00000000000..e76d3c31694 --- /dev/null +++ b/lookups/csv/renamed_lolbas_binaries.yml @@ -0,0 +1,14 @@ +name: renamed_lolbas_binaries +id: 8fcee872-392f-41ab-95fb-a50f8557b03e +version: 1 +creation_date: '2026-09-23' +modification_date: '2026-09-23' +author: Splunk Threat Research Team +lookup_type: csv +description: A list of LOLBAS binaries and detailed information regarding their usage +default_match: 'false' +match_type: + - WILDCARD(original_file_name) +min_matches: 1 +max_matches: 1 +case_sensitive_match: false diff --git a/lookups/csv/renamed_popular_3rd_party_binaries.csv b/lookups/csv/renamed_popular_3rd_party_binaries.csv new file mode 100644 index 00000000000..d2a52926d0d --- /dev/null +++ b/lookups/csv/renamed_popular_3rd_party_binaries.csv @@ -0,0 +1,43 @@ +original_file_name,description +7z.exe,7-Zip +7zg.exe,7-Zip +7zfm.exe,7-Zip +7za.exe,7-Zip +winrar*.exe,WinRAR +rar.exe,WinRAR +unrar.exe,WinRAR +peazip.exe,PeaZip +anydesk.exe,AnyDesk +teamviewer*.exe,TeamViewer +tv_w32.exe,TeamViewer +tv_x64.exe,TeamViewer +screenconnect*.exe,ConnectWise ScreenConnect +ateraagent.exe,Atera +srserver.exe,Splashtop +splashtopstreamer.exe,Splashtop +lmiguardiansvc.exe,LogMeIn +logmein.exe,LogMeIn +basupsrvc.exe,N-able Take Control +tcclient.exe,N-able Take Control +action1_agent.exe,Action1 +rutserv.exe,Remote Utilities +rfusclient.exe,Remote Utilities +advanced_ip_scanner*.exe,Advanced IP Scanner +advanced_port_scanner*.exe,Advanced Port Scanner +netscan.exe,SoftPerfect Network Scanner +ipscan.exe,Angry IP Scanner +adfind*.exe,AdFind +processhacker.exe,Process Hacker +systeminformer.exe,System Informer +winscp*.exe,WinSCP +rclone.exe,Rclone +plink.exe,PuTTY +putty*.exe,PuTTY +mobaxterm.exe,MobaXterm +ngrok.exe,Ngrok +cloudflared.exe,Cloudflared +chisel.exe,Chisel +webbrowserpassview.exe,NirSoft WebBrowserPassView +mailpv.exe,NirSoft Mail PassView +autoit3.exe,AutoIt +aut2exe.exe,AutoIt diff --git a/lookups/csv/renamed_popular_3rd_party_binaries.yml b/lookups/csv/renamed_popular_3rd_party_binaries.yml new file mode 100644 index 00000000000..0c684fe5e13 --- /dev/null +++ b/lookups/csv/renamed_popular_3rd_party_binaries.yml @@ -0,0 +1,14 @@ +name: renamed_popular_3rd_party_binaries +id: 83a56371-0a0f-4486-be21-8dc1d4d25e97 +version: 1 +creation_date: '2026-09-23' +modification_date: '2026-09-23' +author: Splunk Threat Research Team +lookup_type: csv +description: A list of popular 3rd party Windows binaries and their software names +default_match: 'false' +match_type: + - WILDCARD(original_file_name) +min_matches: 1 +max_matches: 1 +case_sensitive_match: false diff --git a/lookups/csv/renamed_windows_command_interpreter_binaries.csv b/lookups/csv/renamed_windows_command_interpreter_binaries.csv new file mode 100644 index 00000000000..8809169991f --- /dev/null +++ b/lookups/csv/renamed_windows_command_interpreter_binaries.csv @@ -0,0 +1,14 @@ +original_file_name,description +bash.exe,"Bourne Again Shell interpreter; ships with WSL/Git for Windows/Cygwin and executes shell scripts and commands." +cmd.exe,"The native Windows command-line interpreter used to execute batch scripts and commands." +powershell.exe,"Windows PowerShell (v5.1 and earlier) command-line shell and scripting engine, heavily used for administration and living-off-the-land attacks." +powershell_ise.exe,"PowerShell Integrated Scripting Environment; GUI host for writing and running PowerShell scripts." +psexec*.c,"Sysinternals tool for executing processes on remote systems; frequently abused for lateral movement." +psexec*.exe,"Sysinternals tool for executing processes on remote systems; frequently abused for lateral movement." +psexec64.exe,"64-bit build of the Sysinternals PsExec remote execution tool." +pwsh.exe,"PowerShell (Core) 6+ cross-platform command-line shell and scripting engine, successor to powershell.exe." +pwsh.dll,"PowerShell (Core) 6+ cross-platform command-line shell and scripting engine, successor to powershell.exe." +sh.exe,"POSIX-compatible shell interpreter, typically bundled with Git for Windows/WSL/Cygwin, used to run shell scripts." +windowsterminal.exe,"Modern Windows Terminal application host that runs command-line shells (cmd, PowerShell, WSL) in tabs." +wsl.exe,"Windows Subsystem for Linux launcher; runs a Linux distribution/shell and executes Linux binaries or scripts on Windows." +wt.exe,"Windows Terminal executable, invoked via the wt command; launches and hosts terminal shell sessions." diff --git a/lookups/csv/renamed_windows_command_interpreter_binaries.yml b/lookups/csv/renamed_windows_command_interpreter_binaries.yml new file mode 100644 index 00000000000..0e364ef511c --- /dev/null +++ b/lookups/csv/renamed_windows_command_interpreter_binaries.yml @@ -0,0 +1,14 @@ +name: renamed_windows_command_interpreter_binaries +id: 2517d9fc-a1ee-4303-9a5b-15eaee7f418b +version: 1 +creation_date: '2026-09-23' +modification_date: '2026-09-23' +author: Splunk Threat Research Team +lookup_type: csv +description: A list of Windows command interpreter binaries and detailed information regarding their usage +default_match: 'false' +match_type: + - WILDCARD(original_file_name) +min_matches: 1 +max_matches: 1 +case_sensitive_match: false