276. Hunting for Suspicious IIS Modules

Hello everyone!

Let's talk about another uncommon technique - Server Software Component: IIS Components (T1505.004), and how to hunt for installation of suspicious modules.

According to the reportUAT-8099 leveraged appcmd.exe to install and uninstall IIS modules:

c:\windows\System32\inetsrv\appcmd.exe uninstall module /module.name:HttpFastCgiModule

c:\windows\SysWOW64\inetsrv\appcmd.exe install module /name:HttpCgiModule /image:%windir%\SysWOW64\inetsrv\HttpCgiModule.dll /preCondition:bitness32

This behavior can be transformed into a hunting query:

event_type: "processcreatewin"

AND

proc_file_path: "appcmd.exe"

AND

cmdline: ("module" AND ("install" OR "uninstall"))

See you tomorrow!

Comments

Popular posts from this blog

033. Free Google Threat Intelligence Course

082. Huniting for Malicious Browser Extensions

068. Detecting RMMs from Ransomware Affiliate's Toolkit: MeshAgent