Suspicious MS Office Child Process

edit

Identifies suspicious child processes of frequently targeted Microsoft Office applications (Word, PowerPoint, Excel). These child processes are often launched during exploitation of Office applications or from documents with malicious macros.

Rule type: eql

Rule indices:

  • winlogbeat-*
  • logs-endpoint.events.*
  • logs-windows.*

Severity: medium

Risk score: 47

Runs every: 5 minutes

Searches indices from: now-9m (Date Math format, see also Additional look-back time)

Maximum alerts per execution: 100

Tags:

  • Elastic
  • Host
  • Windows
  • Threat Detection
  • Initial Access

Version: 10 (version history)

Added (Elastic Stack release): 7.6.0

Last modified (Elastic Stack release): 8.2.0

Rule authors: Elastic

Rule license: Elastic License v2

Investigation guide

edit
## Config

If enabling an EQL rule on a non-elastic-agent index (such as beats) for versions <8.2, events will not define `event.ingested` and default fallback for EQL rules was not added until 8.2, so you will need to add a custom pipeline to populate `event.ingested` to @timestamp for this rule to work.

Rule query

edit
process where event.type in ("start", "process_started") and
process.parent.name : ("eqnedt32.exe", "excel.exe", "fltldr.exe",
"msaccess.exe", "mspub.exe", "powerpnt.exe", "winword.exe") and
process.name : ("Microsoft.Workflow.Compiler.exe", "arp.exe",
"atbroker.exe", "bginfo.exe", "bitsadmin.exe", "cdb.exe",
"certutil.exe", "cmd.exe", "cmstp.exe", "control.exe",
"cscript.exe", "csi.exe", "dnx.exe", "dsget.exe", "dsquery.exe",
"forfiles.exe", "fsi.exe", "ftp.exe", "gpresult.exe",
"hostname.exe", "ieexec.exe", "iexpress.exe", "installutil.exe",
"ipconfig.exe", "mshta.exe", "msxsl.exe",
"nbtstat.exe", "net.exe", "net1.exe", "netsh.exe", "netstat.exe",
"nltest.exe", "odbcconf.exe", "ping.exe",
"powershell.exe", "pwsh.exe", "qprocess.exe", "quser.exe",
"qwinsta.exe", "rcsi.exe", "reg.exe", "regasm.exe",
"regsvcs.exe", "regsvr32.exe", "sc.exe", "schtasks.exe",
"systeminfo.exe", "tasklist.exe", "tracert.exe", "whoami.exe",
"wmic.exe", "wscript.exe", "xwizard.exe", "explorer.exe",
"rundll32.exe", "hh.exe")

Threat mapping

edit

Framework: MITRE ATT&CKTM

Rule version history

edit
Version 10 (8.2.0 release)
  • Formatting only
Version 9 (7.16.0 release)
  • Updated query, changed from:

    process where event.type in ("start", "process_started") and
    process.parent.name : ("eqnedt32.exe", "excel.exe", "fltldr.exe",
    "msaccess.exe", "mspub.exe", "powerpnt.exe", "winword.exe") and
    process.name : ("Microsoft.Workflow.Compiler.exe", "arp.exe",
    "atbroker.exe", "bginfo.exe", "bitsadmin.exe", "cdb.exe",
    "certutil.exe", "cmd.exe", "cmstp.exe", "cscript.exe",
    "csi.exe", "dnx.exe", "dsget.exe", "dsquery.exe", "forfiles.exe",
    "fsi.exe", "ftp.exe", "gpresult.exe", "hostname.exe",
    "ieexec.exe", "iexpress.exe", "installutil.exe", "ipconfig.exe",
    "mshta.exe", "msxsl.exe", "nbtstat.exe", "net.exe",
    "net1.exe", "netsh.exe", "netstat.exe", "nltest.exe", "odbcconf.exe",
    "ping.exe", "powershell.exe", "pwsh.exe",
    "qprocess.exe", "quser.exe", "qwinsta.exe", "rcsi.exe", "reg.exe",
    "regasm.exe", "regsvcs.exe", "regsvr32.exe", "sc.exe",
    "schtasks.exe", "systeminfo.exe", "tasklist.exe", "tracert.exe",
    "whoami.exe", "wmic.exe", "wscript.exe",
    "xwizard.exe", "explorer.exe", "rundll32.exe", "hh.exe")
Version 8 (7.12.0 release)
  • Formatting only
Version 7 (7.11.2 release)
  • Formatting only
Version 6 (7.11.0 release)
  • Updated query, changed from:

    event.category:process and event.type:(start or process_started) and
    process.parent.name:(eqnedt32.exe or excel.exe or fltldr.exe or
    msaccess.exe or mspub.exe or powerpnt.exe or winword.exe) and
    process.name:(Microsoft.Workflow.Compiler.exe or arp.exe or
    atbroker.exe or bginfo.exe or bitsadmin.exe or cdb.exe or certutil.exe
    or cmd.exe or cmstp.exe or cscript.exe or csi.exe or dnx.exe or
    dsget.exe or dsquery.exe or forfiles.exe or fsi.exe or ftp.exe or
    gpresult.exe or hostname.exe or ieexec.exe or iexpress.exe or
    installutil.exe or ipconfig.exe or mshta.exe or msxsl.exe or
    nbtstat.exe or net.exe or net1.exe or netsh.exe or netstat.exe or
    nltest.exe or odbcconf.exe or ping.exe or powershell.exe or pwsh.exe
    or qprocess.exe or quser.exe or qwinsta.exe or rcsi.exe or reg.exe or
    regasm.exe or regsvcs.exe or regsvr32.exe or sc.exe or schtasks.exe or
    systeminfo.exe or tasklist.exe or tracert.exe or whoami.exe or
    wmic.exe or wscript.exe or xwizard.exe)
Version 5 (7.10.0 release)
  • Formatting only
Version 4 (7.9.1 release)
  • Formatting only
Version 3 (7.9.0 release)
  • Updated query, changed from:

    event.action:"Process Create (rule: ProcessCreate)" and
    process.parent.name:(eqnedt32.exe or excel.exe or fltldr.exe or
    msaccess.exe or mspub.exe or powerpnt.exe or winword.exe) and
    process.name:(Microsoft.Workflow.Compiler.exe or arp.exe or
    atbroker.exe or bginfo.exe or bitsadmin.exe or cdb.exe or certutil.exe
    or cmd.exe or cmstp.exe or cscript.exe or csi.exe or dnx.exe or
    dsget.exe or dsquery.exe or forfiles.exe or fsi.exe or ftp.exe or
    gpresult.exe or hostname.exe or ieexec.exe or iexpress.exe or
    installutil.exe or ipconfig.exe or mshta.exe or msxsl.exe or
    nbtstat.exe or net.exe or net1.exe or netsh.exe or netstat.exe or
    nltest.exe or odbcconf.exe or ping.exe or powershell.exe or pwsh.exe
    or qprocess.exe or quser.exe or qwinsta.exe or rcsi.exe or reg.exe or
    regasm.exe or regsvcs.exe or regsvr32.exe or sc.exe or schtasks.exe or
    systeminfo.exe or tasklist.exe or tracert.exe or whoami.exe or
    wmic.exe or wscript.exe or xwizard.exe)
Version 2 (7.7.0 release)
  • Updated query, changed from:

    event.action:"Process Create (rule: ProcessCreate)" and
    process.parent.name:("winword.exe" or "excel.exe" or "powerpnt.exe" or
    "eqnedt32.exe" or "fltldr.exe" or "mspub.exe" or "msaccess.exe") and
    process.name:("arp.exe" or "dsquery.exe" or "dsget.exe" or
    "gpresult.exe" or "hostname.exe" or "ipconfig.exe" or "nbtstat.exe" or
    "net.exe" or "net1.exe" or "netsh.exe" or "netstat.exe" or
    "nltest.exe" or "ping.exe" or "qprocess.exe" or "quser.exe" or
    "qwinsta.exe" or "reg.exe" or "sc.exe" or "systeminfo.exe" or
    "tasklist.exe" or "tracert.exe" or "whoami.exe" or "bginfo.exe" or
    "cdb.exe" or "cmstp.exe" or "csi.exe" or "dnx.exe" or "fsi.exe" or
    "ieexec.exe" or "iexpress.exe" or "installutil.exe" or
    "Microsoft.Workflow.Compiler.exe" or "msbuild.exe" or "mshta.exe" or
    "msxsl.exe" or "odbcconf.exe" or "rcsi.exe" or "regsvr32.exe" or
    "xwizard.exe" or "atbroker.exe" or "forfiles.exe" or "schtasks.exe" or
    "regasm.exe" or "regsvcs.exe" or "cmd.exe" or "cscript.exe" or
    "powershell.exe" or "pwsh.exe" or "wmic.exe" or "wscript.exe" or
    "bitsadmin.exe" or "certutil.exe" or "ftp.exe")