Detection rules › Sigma
LPE InstallerFileTakeOver PoC CVE-2021-41379
Detects PoC tool used to exploit LPE vulnerability CVE-2021-41379
Known false positives
- Other MSI packages for which your admins have used that name
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Initial Access |
Telemetry coverage
| Provider | Record / event type |
|---|---|
| MsiInstaller | Event ID 1033: Windows Installer installed the product. |
Rule body
title: LPE InstallerFileTakeOver PoC CVE-2021-41379
id: 7dbb86de-a0cc-494c-8aa8-b2996c9ef3c8
status: test
description: Detects PoC tool used to exploit LPE vulnerability CVE-2021-41379
references:
- https://web.archive.org/web/20220421061949/https://github.com/klinix5/InstallerFileTakeOver
author: Florian Roth (Nextron Systems)
date: 2021-11-22
modified: 2022-07-12
tags:
- attack.initial-access
- attack.t1190
- detection.emerging-threats
logsource:
product: windows
service: application
# warning: The 'data' field used in the detection section is the container for the event data as a whole. You may have to adapt the rule for your backend accordingly
detection:
selection:
EventID: 1033
Provider_Name: 'MsiInstaller'
Data|contains: 'test pkg'
condition: selection
falsepositives:
- Other MSI packages for which your admins have used that name
level: high
Stages and Predicates
Stage 0: condition
selectionStage 1: selection
selection:
EventID: 1033
Provider_Name: 'MsiInstaller'
Data|contains: 'test pkg'
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
Data | match |
| field:"Data" kind:match value:"test pkg" |
Provider_Name | eq |
| field:"Provider_Name" kind:eq value:"MsiInstaller" |