Detection rules › Sigma

PUA - Seatbelt Execution

Severity
high
Author
Nasreddine Bencherchali (Nextron Systems)
Source
upstream

Detects the execution of the PUA/Recon tool Seatbelt via PE information of command line parameters

MITRE ATT&CK coverage

TacticTechniques
DiscoveryT1083 File and Directory Discovery, T1087 Account Discovery, T1526 Cloud Service Discovery

Event coverage

ProviderEvent IDTitle
Sysmon1Process creation

Stages and Predicates

Stage 1: selection_img

or:
CommandLine|contains: ' CertificateThumbprints'
CommandLine|contains: ' ChromiumBookmarks'
CommandLine|contains: ' ChromiumHistory'
CommandLine|contains: ' ChromiumPresence'
CommandLine|contains: ' CloudCredentials'
CommandLine|contains: ' CredEnum'
CommandLine|contains: ' CredGuard'
CommandLine|contains: ' DpapiMasterKeys'
CommandLine|contains: ' FirefoxHistory'
CommandLine|contains: ' InterestingFiles'
CommandLine|contains: ' InterestingProcesses'
CommandLine|contains: ' ProcessCreationEvents'
Description: Seatbelt
Image|endswith: '\Seatbelt.exe'
OriginalFileName: Seatbelt.exe

Stage 2: all of selection_group_list

or:
CommandLine|contains: ' -group=all'
CommandLine|contains: ' -group=chromium'
CommandLine|contains: ' -group=misc'
CommandLine|contains: ' -group=remote'
CommandLine|contains: ' -group=slack'
CommandLine|contains: ' -group=system'
CommandLine|contains: ' -group=user'

Stage 3: all of selection_group_output

CommandLine|contains: ' -outputfile='

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
CommandLinematch
  • -group=all
  • -group=chromium
  • -group=misc
  • -group=remote
  • -group=slack
  • -group=system
  • -group=user
  • -outputfile=
  • CertificateThumbprints
  • ChromiumBookmarks
  • ChromiumHistory
  • ChromiumPresence
  • CloudCredentials
  • CredEnum
  • CredGuard
  • DpapiMasterKeys
  • FirefoxHistory
  • InterestingFiles
  • InterestingProcesses
  • ProcessCreationEvents
Descriptioneq
  • Seatbelt
Imageends_with
  • \Seatbelt.exe
OriginalFileNameeq
  • Seatbelt.exe