Detection rules › Splunk
PuTTY Secure Copy Client Execution (PowerShell)
pscp.exe is a tool in the PuTTY suite used for secure copy and has been used by threat actors including BlackCat and Agrius to exfiltrate data. This use case detects executions of pscp.exe.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Exfiltration |
References
Telemetry coverage
| Provider | Record / event type |
|---|---|
| PowerShell | Event ID 4104: Creating Scriptblock text (MessageNumber of MessageTotal). |
Rule body
id: '24501.45206'
title: PuTTY Secure Copy Client Execution
description: pscp.exe is a tool in the PuTTY suite used for secure copy and has been
used by threat actors including BlackCat and Agrius to exfiltrate data. This use
case detects executions of pscp.exe.
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_powershell` (TERM(EventCode=4104) OR
"<EventID>4104<") "pscp.exe" | table _time, host, user process, process_*, signature_id,
parent_* | bin span=60s | stats values(*) as * by _time, host '
techniques:
- exfiltration:exfiltration over alternative protocol
technique_id:
- T1048
data_category:
- PowerShell logs
references:
- https://unit42.paloaltonetworks.com/agonizing-serpens-targets-israeli-tech-higher-ed-sectors/
- https://www.trendmicro.com/en_us/research/23/f/malvertising-used-as-entry-vector-for-blackcat-actors-also-lever.html
Stages and Predicates
Stage 1: search
`get_endpoint_data` `get_endpoint_data_powershell` (TERM(EventCode=4104) OR "<EventID>4104<") "pscp.exe"
Stage 2: table
| table _time, host, user process, process_*, signature_id, parent_*
Stage 3: bucket
| bin span=60s
Stage 4: stats
| stats values(*) as * by _time, host
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
EventCode | eq |
| field:"EventID" kind:eq value:"4104" |
Search terms
These SPL tokens match against raw event text.
| Stage | Term |
|---|---|
| 1 | "<EventID>4104<" |
| 1 | "pscp.exe" |