Detection rules › Equivalence class

eq_0002 — 2 rules with the same canonical form

Vendors: sigma (2). Stage count: 2. Correlation shape: alternatives_cross_log.

Members

MITRE ATT&CK coverage

TacticTechniques
Defense EvasionT1218 System Binary Proxy Execution

Stages and predicates (per member)

Each member's stage rendered in its own native syntax (verbatim source where the IR captures it; falls back to the synthesised native form for the few stage types whose source segments aren't recoverable).

Potential Provlaunch.EXE Binary Proxy Execution Abuse — stage 1 selection

ParentImage|endswith: '\provlaunch.exe'

Potential Provlaunch.EXE Binary Proxy Execution Abuse — stage 2 not 1 of filter_main_covered_children

or:
Image|endswith: '\calc.exe'
Image|endswith: '\cmd.exe'
Image|endswith: '\cscript.exe'
Image|endswith: '\mshta.exe'
Image|endswith: '\notepad.exe'
Image|endswith: '\powershell.exe'
Image|endswith: '\pwsh.exe'
Image|endswith: '\regsvr32.exe'
Image|endswith: '\rundll32.exe'
Image|endswith: '\wscript.exe'
Image|contains: ':\PerfLogs\'
Image|contains: ':\Temp\'
Image|contains: ':\Users\Public\'
Image|contains: '\AppData\Temp\'
Image|contains: '\Windows\System32\Tasks\'
Image|contains: '\Windows\Tasks\'
Image|contains: '\Windows\Temp\'

Suspicious Provlaunch.EXE Child Process — stage 3 all of selection_parent

ParentImage|endswith: '\provlaunch.exe'

Suspicious Provlaunch.EXE Child Process — stage 4 all of selection_child

or:
Image|endswith: '\calc.exe'
Image|endswith: '\cmd.exe'
Image|endswith: '\cscript.exe'
Image|endswith: '\mshta.exe'
Image|endswith: '\notepad.exe'
Image|endswith: '\powershell.exe'
Image|endswith: '\pwsh.exe'
Image|endswith: '\regsvr32.exe'
Image|endswith: '\rundll32.exe'
Image|endswith: '\wscript.exe'
Image|contains: ':\PerfLogs\'
Image|contains: ':\Temp\'
Image|contains: ':\Users\Public\'
Image|contains: '\AppData\Temp\'
Image|contains: '\Windows\System32\Tasks\'
Image|contains: '\Windows\Tasks\'
Image|contains: '\Windows\Temp\'

Indicators (across all members)

FieldKindValueMembersCorpus
Imageends_with\calc.exe213
Imageends_with\cmd.exe292
Imageends_with\cscript.exe264
Imageends_with\mshta.exe257
Imageends_with\notepad.exe211
Imageends_with\powershell.exe2143
Imageends_with\pwsh.exe2140
Imageends_with\regsvr32.exe257
Imageends_with\rundll32.exe276
Imageends_with\wscript.exe264
Imagematch:\PerfLogs\24
Imagematch:\Temp\212
Imagematch:\Users\Public\214
Imagematch\AppData\Temp\23
Imagematch\Windows\System32\Tasks\24
Imagematch\Windows\Tasks\24
Imagematch\Windows\Temp\27
ParentImageends_with\provlaunch.exe22