Detection rules › Splunk

Dotnet.exe Execution (Windows Event Log)

Group by
_time, host
Source
github.com/anvilogic-forge/armory

dotnet.exe comes with .NET Framework, is trusted binary and Default AppLocker rule does not block it so it will execute any dll even if applocker is enabled

MITRE ATT&CK coverage

References

Telemetry coverage

Rule body

id: '6582.7595'
title: Dotnet.exe Execution
description: dotnet.exe comes with .NET Framework, is trusted binary and Default AppLocker
  rule does not block it so it will execute any dll even if applocker is enabled.
  Living Off the Land Binary and Scripts (LOLBAS) (LOLBIN)
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4688) OR
  "<EventID>4688<") ("dotnet") | table _time, host, user user, process, process_*,
  parent_* | bin span=1s | stats values(*) as * by _time, host '
techniques:
- defense-evasion:system binary proxy execution
technique_id: 
- T1218
data_category:
- Windows event logs
references:
- https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/
- https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/

Stages and Predicates

Stage 1: search

`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4688) OR "<EventID>4688<") ("dotnet")

Stage 2: table

| table _time, host, user user, process, process_*, parent_*

Stage 3: bucket

| bin span=1s

Stage 4: stats

| stats values(*) as * by _time, host

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
EventCodeeq
  • 4688 corpus 317 (splunk 283, kusto 33, elastic 1)
field:"EventID" kind:eq value:"4688"

Search terms

These SPL tokens match against raw event text.

StageTerm
1"<EventID>4688<"
1"dotnet"