Detection rules › Sigma

Suspicious VBoxDrvInst.exe Parameters

Status
test
Severity
medium
Log source
category process_creation, product windows
Author
Konstantin Grishchenko, oscd.community
Source
github.com/SigmaHQ/sigma

Detect VBoxDrvInst.exe run with parameters allowing processing INF file. This allows to create values in the registry and install drivers. For example one could use this technique to obtain persistence via modifying one of Run or RunOnce registry keys

Known false positives

  • Legitimate use of VBoxDrvInst.exe utility by VirtualBox Guest Additions installation process

MITRE ATT&CK coverage

TacticTechniques
Persistence
Defense Impairment

Telemetry coverage

Rule body

title: Suspicious VBoxDrvInst.exe Parameters
id: b7b19cb6-9b32-4fc4-a108-73f19acfe262
status: test
description: |
  Detect VBoxDrvInst.exe run with parameters allowing processing INF file.
  This allows to create values in the registry and install drivers.
  For example one could use this technique to obtain persistence via modifying one of Run or RunOnce registry keys
references:
    - https://github.com/LOLBAS-Project/LOLBAS/blob/4db780e0f0b2e2bb8cb1fa13e09196da9b9f1834/yml/LOLUtilz/OtherBinaries/VBoxDrvInst.yml
    - https://twitter.com/pabraeken/status/993497996179492864
author: Konstantin Grishchenko, oscd.community
date: 2020-10-06
modified: 2021-11-27
tags:
    - attack.persistence
    - attack.defense-impairment
    - attack.t1112
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        Image|endswith: '\VBoxDrvInst.exe'
        CommandLine|contains|all:
            - 'driver'
            - 'executeinf'
    condition: selection
falsepositives:
    - Legitimate use of VBoxDrvInst.exe utility by VirtualBox Guest Additions installation process
level: medium

Stages and Predicates

Stage 0: condition

selection

Stage 1: selection

selection:
    Image|endswith: '\VBoxDrvInst.exe'
    CommandLine|contains|all:
        - 'driver'
        - 'executeinf'

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
CommandLinematch
  • driver
  • executeinf
field:"CommandLine" kind:match
Imageends_with
  • \VBoxDrvInst.exe
field:"Image" kind:ends_with value:"\VBoxDrvInst.exe"