Detection rules › Sigma

Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp

Severity
high
Author
Aaron Stratton
Source
upstream

Detects suspicious child processes of Excel which could be an indicator of lateral movement leveraging the "ActivateMicrosoftApp" Excel DCOM object.

MITRE ATT&CK coverage

TacticTechniques
Lateral MovementT1021.003 Remote Services: Distributed Component Object Model

Event coverage

ProviderEvent IDTitle
Sysmon1Process creation

Stages and Predicates

Stage 1: all of selection_parent

ParentImage|endswith: '\excel.exe'

Stage 2: all of selection_child

or:
Image|endswith: '\foxprow.exe'
Image|endswith: '\schdplus.exe'
Image|endswith: '\winproj.exe'
OriginalFileName: foxprow.exe
OriginalFileName: schdplus.exe
OriginalFileName: winproj.exe

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
Imageends_with
  • \foxprow.exe
  • \schdplus.exe
  • \winproj.exe
OriginalFileNameeq
  • foxprow.exe
  • schdplus.exe
  • winproj.exe
ParentImageends_with
  • \excel.exe corpus 2 (sigma 2)