Detection rules › Elastic

Network Connection via Startup Item

Time window
1m
Sequence by
process.entity_id
Source
github.com/elastic/protections-artifacts

Identifies the execution of an unsigned program or script from the Startup shell folder followed by an immediate network connection. This may indicate the presence of a malicious persistent item.

MITRE ATT&CK coverage

Rule body

[rule]
description = """
Identifies the execution of an unsigned program or script from the Startup shell folder followed by an immediate network
connection. This may indicate the presence of a malicious persistent item.
"""
id = "0b33141a-3f73-4414-ba90-d8410e6ab176"
license = "Elastic License v2"
name = "Network Connection via Startup Item"
os_list = ["windows"]
version = "1.0.31"

query = '''
sequence by process.entity_id with maxspan=1m
 [process where event.action == "start" and
  (
   // unsigned program starting from startup folder
   (process.executable : (
    "?:\\Users\\*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*",
    "?:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*")  and
    not process.code_signature.trusted == true) or

    // Scripts starting from startup folder
   (process.name : ("cscript.exe", "wscript.exe", "mshta.exe", "powershell.exe") and
    process.command_line : (
        "*:\\Users\\*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*",
        "*:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*"))
  ) and

  /* ConnectWiseManage - unsigned */
  not process.hash.sha256 : "cac904da410372bcd0797b4bfa402c8f8663040f26e80a435d98d12bd2fa6659"]
 [network where not cidrmatch(destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24",
       "192.0.0.0/29", "192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32",
       "192.0.2.0/24", "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4",
       "100.64.0.0/10", "192.168.0.0/16", "192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1",
       "FE80::/10", "FF00::/8")]
'''

min_endpoint_version = "7.15.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 1

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1059"
name = "Command and Scripting Interpreter"
reference = "https://attack.mitre.org/techniques/T1059/"
[[threat.technique.subtechnique]]
id = "T1059.001"
name = "PowerShell"
reference = "https://attack.mitre.org/techniques/T1059/001/"

[[threat.technique.subtechnique]]
id = "T1059.005"
name = "Visual Basic"
reference = "https://attack.mitre.org/techniques/T1059/005/"

[[threat.technique.subtechnique]]
id = "T1059.007"
name = "JavaScript"
reference = "https://attack.mitre.org/techniques/T1059/007/"



[threat.tactic]
id = "TA0002"
name = "Execution"
reference = "https://attack.mitre.org/tactics/TA0002/"
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1547"
name = "Boot or Logon Autostart Execution"
reference = "https://attack.mitre.org/techniques/T1547/"
[[threat.technique.subtechnique]]
id = "T1547.001"
name = "Registry Run Keys / Startup Folder"
reference = "https://attack.mitre.org/techniques/T1547/001/"



[threat.tactic]
id = "TA0003"
name = "Persistence"
reference = "https://attack.mitre.org/tactics/TA0003/"
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1218"
name = "System Binary Proxy Execution"
reference = "https://attack.mitre.org/techniques/T1218/"
[[threat.technique.subtechnique]]
id = "T1218.005"
name = "Mshta"
reference = "https://attack.mitre.org/techniques/T1218/005/"



[threat.tactic]
id = "TA0005"
name = "Defense Evasion"
reference = "https://attack.mitre.org/tactics/TA0005/"

[internal]
min_endpoint_version = "7.15.0"

Stages and Predicates

Ordered sequence: each step below must occur in order within 1m, correlated by process.entity_id.

Stage 1: process

[process where event.action == "start" and
  (
   (process.executable : (
    "?:\\Users\\*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*",
    "?:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*")  and
    not process.code_signature.trusted == true) or
   (process.name : ("cscript.exe", "wscript.exe", "mshta.exe", "powershell.exe") and
    process.command_line : (
        "*:\\Users\\*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*",
        "*:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*"))
  ) and
  not process.hash.sha256 : "cac904da410372bcd0797b4bfa402c8f8663040f26e80a435d98d12bd2fa6659"]

Stage 2: network

[network where not cidrmatch(destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24",
       "192.0.0.0/29", "192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32",
       "192.0.2.0/24", "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4",
       "100.64.0.0/10", "192.168.0.0/16", "192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1",
       "FE80::/10", "FF00::/8")]

Exclusions

The rule actively suppresses these predicates.

FieldKindExcluded valuesSearch
process.hash.sha256eqcac904da410372bcd0797b4bfa402c8f8663040f26e80a435d98d12bd2fa6659excludes:process.hash.sha256 field:"process.hash.sha256" value:"cac904da410372bcd0797b4bfa402c8f8663040f26e80a435d98d12bd2fa6659"
destination.ipcidr_match10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.0.0.0/24, 192.0.0.0/29, 192.0.0.8/32, 192.0.0.9/32, 192.0.0.10/32, 192.0.0.170/32, 192.0.0.171/32, 192.0.2.0/24, 192.31.196.0/24, 192.52.193.0/24, 192.88.99.0/24, 224.0.0.0/4, 100.64.0.0/10, 192.168.0.0/16, 192.175.48.0/24, 198.18.0.0/15, 198.51.100.0/24, 203.0.113.0/24, 240.0.0.0/4, ::1, FE80::/10, FF00::/8excludes:destination.ip

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
event.actioneq
  • start corpus 391 (elastic 391)
field:"EventType" kind:eq value:"start"
process.command_linewildcard
  • *:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\*
  • *:\Users\*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*
field:"CommandLine" kind:wildcard
process.executablewildcard
  • ?:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\*
  • ?:\Users\*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*
field:"Image" kind:wildcard
process.namewildcard
  • cscript.exe corpus 67 (elastic 65, splunk 2)
  • mshta.exe corpus 84 (elastic 79, splunk 5)
  • powershell.exe corpus 184 (elastic 140, splunk 44)
  • wscript.exe corpus 83 (elastic 82, splunk 1)
field:"process_name" kind:wildcard