Detection rules › Splunk

Windows Process Injection Remote Thread

Author
Teoderick Contreras, Splunk
Source
upstream

The following analytic detects suspicious remote thread execution in processes such as Taskmgr.exe, calc.exe, and notepad.exe, which may indicate process injection by malware like Qakbot. This detection leverages Sysmon EventCode 8 to identify remote thread creation in specific target processes. This activity is significant as it often signifies an attempt by malware to inject malicious code into legitimate processes, potentially leading to unauthorized code execution. If confirmed malicious, this could allow attackers to execute arbitrary code, escalate privileges, or maintain persistence on the compromised host.

MITRE ATT&CK coverage

TacticTechniques
Privilege EscalationT1055.002 Process Injection: Portable Executable Injection
Defense EvasionT1055.002 Process Injection: Portable Executable Injection

Event coverage

ProviderEvent IDTitle
Sysmon8CreateRemoteThread

Stages and Predicates

Stage 1: search

search EventCode=8 TargetImage IN ("*\\CalculatorApp.exe", "*\\OneDriveSetup.exe", "*\\Taskmgr.exe", "*\\calc.exe", "*\\cmd.exe", "*\\dxdiag.exe", "*\\explorer.exe", "*\\mobsync.exe", "*\\msra.exe", "*\\notepad.exe", "*\\ping.exe", "*\\powershell.exe", "*\\rdpclip.exe", "*\\wermgr.exe", "*\\win32calc.exe", "*\\xwizard.exe")

Stage 2: stats

stats BY EventID, Guid, NewThreadId, ProcessID, SecurityID, SourceImage, SourceProcessGuid, SourceProcessId, StartAddress, StartFunction, StartModule, TargetImage, TargetProcessGuid, TargetProcessId, UserID, dest, parent_process_exec, parent_process_guid, parent_process_id, parent_process_name, parent_process_path, process_exec, process_guid, process_id, process_name, process_path, signature, signature_id, user_id, vendor_product

Stage 3: search

search

Stage 4: search

search

Stage 5: search

search `macro`

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
EventCodeeq
  • 8 corpus 8 (splunk 8)
TargetImagein
  • "*\\CalculatorApp.exe" corpus 2 (splunk 2)
  • "*\\OneDriveSetup.exe"
  • "*\\Taskmgr.exe"
  • "*\\calc.exe" corpus 2 (splunk 2)
  • "*\\cmd.exe" corpus 2 (splunk 2)
  • "*\\dxdiag.exe"
  • "*\\explorer.exe" corpus 2 (splunk 2)
  • "*\\mobsync.exe"
  • "*\\msra.exe"
  • "*\\notepad.exe" corpus 2 (splunk 2)
  • "*\\ping.exe"
  • "*\\powershell.exe"
  • "*\\rdpclip.exe"
  • "*\\wermgr.exe"
  • "*\\win32calc.exe" corpus 2 (splunk 2)
  • "*\\xwizard.exe"