Detection rules › Splunk
Suspicious ComputerDefaults.exe Execution (Sysmon)
computerdefaults.exe is a legitimate Windows executable handling the Default Programs feature in Windows. This feature allows users to set default programs for specific tasks such as web browsing, email, and media playback. Threat actors may modify the registry to have computerdefaults.exe run arbitrary commands when executed, potentially leading to UAC bypass. This use case detects high or system integrity-level executions of ComputerDefaults.exe that are not initiated from Windows\System32 or Program Files directories
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Privilege Escalation |
References
Telemetry coverage
| Provider | Record / event type |
|---|---|
| Sysmon | Event ID 1: Process creation |
Rule body
id: '33164.58809'
title: Suspicious ComputerDefaults.exe Execution
description: 'computerdefaults.exe is a legitimate Windows executable handling the
Default Programs feature in Windows. This feature allows users to set default programs
for specific tasks such as web browsing, email, and media playback. Threat actors
may modify the registry to have computerdefaults.exe run arbitrary commands when
executed, potentially leading to UAC bypass. This use case detects high or system
integrity-level executions of ComputerDefaults.exe that are not initiated from Windows\System32
or Program Files directories. Atomics T1548.002 Test #5 Living Off the Land Binary
and Scripts (LOLBAS) (LOLBIN)'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_sysmon` (TERM(EventCode=1) OR "<EventID>1<")
"ComputerDefaults.exe" (IntegrityLevel="High" OR IntegrityLevel="System") | regex
parent_process_path!="(?i):\x5c(Windows\x5cSystem32|Program\sFiles)"| regex process_path="(?i)\x5cComputerDefaults\.exe"
| table _time, host, user ObjectName, process, process_*, parent_process_name |
bin span=1s | stats values(*) as * by _time, host '
techniques:
- privilege-escalation:abuse elevation control mechanism:bypass user account control
technique_id:
- T1548.002
data_category:
- Windows Sysmon
references:
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1548.002/T1548.002.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_uac_bypass_computerdefaults.yml
Stages and Predicates
Stage 1: search
`get_endpoint_data` `get_endpoint_data_sysmon` (TERM(EventCode=1) OR "<EventID>1<") "ComputerDefaults.exe" (IntegrityLevel="High" OR IntegrityLevel="System")
Stage 2: regex
| regex parent_process_path!="(?i):\x5c(Windows\x5cSystem32|Program\sFiles)"
Stage 3: regex
| regex process_path="(?i)\x5cComputerDefaults\.exe"
Stage 4: table
| table _time, host, user ObjectName, process, process_*, parent_process_name
Stage 5: bucket
| bin span=1s
Stage 6: stats
| stats values(*) as * by _time, host
Exclusions
The rule actively suppresses these predicates.
| Field | Kind | Excluded values | Search |
|---|---|---|---|
parent_process_path | regex_match | "(?i):\x5c(Windows\x5cSystem32|Program\sFiles)" | excludes:parent_process_path |
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
EventCode | eq |
| field:"EventID" kind:eq value:"1" |
IntegrityLevel | eq |
| field:"IntegrityLevel" kind:eq |
process_path | regex_match |
| field:"process_name" kind:regex_match |
Search terms
These SPL tokens match against raw event text.
| Stage | Term |
|---|---|
| 1 | "<EventID>1<" |
| 1 | "ComputerDefaults.exe" |