Detection rules › Sigma

WMImplant Hack Tool

Severity
high
Author
NVISO
Source
upstream

Detects parameters used by WMImplant

MITRE ATT&CK coverage

TacticTechniques
ExecutionT1047 Windows Management Instrumentation, T1059.001 Command and Scripting Interpreter: PowerShell

Event coverage

ProviderEvent IDTitle
PowerShell4104Creating Scriptblock text (MessageNumber of MessageTotal).

Stages and Predicates

Stage 1: selection

or:
ScriptBlockText|contains: ' active_users '
ScriptBlockText|contains: ' basic_info '
ScriptBlockText|contains: ' change_user '
ScriptBlockText|contains: ' command_exec '
ScriptBlockText|contains: ' disable_wdigest '
ScriptBlockText|contains: ' disable_winrm '
ScriptBlockText|contains: ' enable_wdigest '
ScriptBlockText|contains: ' enable_winrm '
ScriptBlockText|contains: ' gen_cli '
ScriptBlockText|contains: ' logon_events '
ScriptBlockText|contains: ' power_off '
ScriptBlockText|contains: ' process_kill '
ScriptBlockText|contains: ' registry_mod '
ScriptBlockText|contains: ' remote_posh '
ScriptBlockText|contains: ' sched_job '
ScriptBlockText|contains: ' service_mod '
ScriptBlockText|contains: ' vacant_system '
ScriptBlockText|contains: WMImplant

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
ScriptBlockTextmatch
  • active_users
  • basic_info
  • change_user
  • command_exec
  • disable_wdigest
  • disable_winrm
  • enable_wdigest
  • enable_winrm
  • gen_cli
  • logon_events
  • power_off
  • process_kill
  • registry_mod
  • remote_posh
  • sched_job
  • service_mod
  • vacant_system
  • WMImplant

Neighbors

Broader alternatives (more inclusive than this rule)

These rules match a superset of what this rule catches. They cover the same events plus more. Use them if you want wider coverage and can absorb more false positives.