Detection rules › Sigma

Install New Package Via Winget Local Manifest

Status
test
Severity
medium
Log source
category process_creation, product windows
Author
Sreeman, Florian Roth (Nextron Systems), frack113
Source
github.com/SigmaHQ/sigma

Detects usage of winget to install applications via manifest file. Adversaries can abuse winget to download payloads remotely and execute them. The manifest option enables you to install an application by passing in a YAML file directly to the client. Winget can be used to download and install exe, msi or msix files later.

Known false positives

  • Some false positives are expected in some environment that may use this functionality to install and test their custom applications

MITRE ATT&CK coverage

Telemetry coverage

ProviderRecord / event type
SysmonEvent ID 1: Process creation

Rule body

title: Install New Package Via Winget Local Manifest
id: 313d6012-51a0-4d93-8dfc-de8553239e25
status: test
description: |
    Detects usage of winget to install applications via manifest file. Adversaries can abuse winget to download payloads remotely and execute them.
    The manifest option enables you to install an application by passing in a YAML file directly to the client.
    Winget can be used to download and install exe, msi or msix files later.
references:
    - https://learn.microsoft.com/en-us/windows/package-manager/winget/install#local-install
    - https://lolbas-project.github.io/lolbas/Binaries/Winget/
    - https://github.com/nasbench/Misc-Research/tree/b9596e8109dcdb16ec353f316678927e507a5b8d/LOLBINs/Winget
author: Sreeman, Florian Roth (Nextron Systems), frack113
date: 2020-04-21
modified: 2023-04-17
tags:
    - attack.execution
    - attack.t1059
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        - Image|endswith: '\winget.exe'
        - OriginalFileName: 'winget.exe'
    selection_install_flag:
        CommandLine|contains:
            - 'install'
            - ' add ' # https://github.com/microsoft/winget-cli/blob/02d2f93807c9851d73eaacb4d8811a76b64b7b01/src/AppInstallerCLICore/Commands/InstallCommand.h
    selection_manifest_flag:
        CommandLine|contains:
            - '-m '
            - '--manifest'
    condition: all of selection_*
falsepositives:
    - Some false positives are expected in some environment that may use this functionality to install and test their custom applications
level: medium

Stages and Predicates

Stage 0: condition

all of selection_*

Stage 1: selection_img

selection_img:
    - Image|endswith: '\winget.exe'
    - OriginalFileName: 'winget.exe'

Stage 2: selection_install_flag

selection_install_flag:
    CommandLine|contains:
        - 'install'
        - ' add '

Stage 3: selection_manifest_flag

selection_manifest_flag:
    CommandLine|contains:
        - '-m '
        - '--manifest'

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
CommandLinematch
  • add corpus 15 (sigma 13, splunk 1, chronicle 1)
  • --manifest
  • -m corpus 4 (sigma 4)
  • install corpus 5 (sigma 5)
field:"CommandLine" kind:match
Imageends_with
  • \winget.exe corpus 5 (sigma 5)
field:"Image" kind:ends_with value:"\winget.exe"
OriginalFileNameeq
  • winget.exe corpus 4 (sigma 4)
field:"OriginalFileName" kind:eq value:"winget.exe"