Detection rules › Sigma

System Network Connections Discovery Via Net.EXE

Status
test
Severity
low
Log source
category process_creation, product windows
Author
frack113
Source
github.com/SigmaHQ/sigma

Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.

MITRE ATT&CK coverage

Telemetry coverage

ProviderRecord / event type
SysmonEvent ID 1: Process creation

Rule body

title: System Network Connections Discovery Via Net.EXE
id: 1c67a717-32ba-409b-a45d-0fb704a73a81
status: test
description: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
references:
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1049/T1049.md#atomic-test-1---system-network-connections-discovery
author: frack113
date: 2021-12-10
modified: 2023-02-21
tags:
    - attack.discovery
    - attack.t1049
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        - Image|endswith:
              - '\net.exe'
              - '\net1.exe'
        - OriginalFileName:
              - 'net.exe'
              - 'net1.exe'
    selection_cli:
        - CommandLine|endswith:
              - ' use'
              - ' sessions'
        - CommandLine|contains:
              - ' use '
              - ' sessions '
    condition: all of selection_*
falsepositives:
    - Unknown
level: low

Stages and Predicates

Stage 0: condition

all of selection_*

Stage 1: selection_img

selection_img:
    - Image|endswith:
          - '\net.exe'
          - '\net1.exe'
    - OriginalFileName:
          - 'net.exe'
          - 'net1.exe'

Stage 2: selection_cli

selection_cli:
    - CommandLine|endswith:
          - ' use'
          - ' sessions'
    - CommandLine|contains:
          - ' use '
          - ' sessions '

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
CommandLineends_with
  • sessions
  • use
field:"CommandLine" kind:ends_with
CommandLinematch
  • sessions
  • use corpus 6 (sigma 6)
field:"CommandLine" kind:match
Imageends_with
  • \net.exe corpus 49 (sigma 49)
  • \net1.exe corpus 47 (sigma 47)
field:"Image" kind:ends_with
OriginalFileNameeq
  • net.exe corpus 31 (sigma 19, elastic 10, splunk 2)
  • net1.exe corpus 44 (sigma 19, splunk 19, elastic 6)
field:"OriginalFileName" kind:eq