Skip to content

Commit c8d6e32

Browse files
Samirbousw0rk3r
andauthored
Update privilege_escalation_unusual_parentchild_relationship.toml (#4775)
Co-authored-by: Jonhnathan <[email protected]>
1 parent 5b3dac0 commit c8d6e32

File tree

1 file changed

+7
-7
lines changed

1 file changed

+7
-7
lines changed

rules/windows/privilege_escalation_unusual_parentchild_relationship.toml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
creation_date = "2020/02/18"
33
integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel", "crowdstrike"]
44
maturity = "production"
5-
updated_date = "2025/03/20"
5+
updated_date = "2025/06/05"
66

77
[transform]
88
[[transform.osquery]]
@@ -132,8 +132,8 @@ process.parent.name != null and
132132
(
133133
/* suspicious parent processes */
134134
(process.name:"autochk.exe" and not process.parent.name:"smss.exe") or
135-
(process.name:("fontdrvhost.exe", "dwm.exe") and not process.parent.name:("wininit.exe", "winlogon.exe")) or
136-
(process.name:("consent.exe", "RuntimeBroker.exe", "TiWorker.exe") and not process.parent.name:"svchost.exe") or
135+
(process.name:("fontdrvhost.exe", "dwm.exe") and not process.parent.name:("wininit.exe", "winlogon.exe", "dwm.exe")) or
136+
(process.name:("consent.exe", "RuntimeBroker.exe", "TiWorker.exe") and not process.parent.name:("svchost.exe", "Workplace Container Helper.exe")) or
137137
(process.name:"SearchIndexer.exe" and not process.parent.name:"services.exe") or
138138
(process.name:"SearchProtocolHost.exe" and not process.parent.name:("SearchIndexer.exe", "dllhost.exe")) or
139139
(process.name:"dllhost.exe" and not process.parent.name:("services.exe", "svchost.exe")) or
@@ -145,15 +145,15 @@ process.parent.name != null and
145145
(process.name:"LogonUI.exe" and not process.parent.name:("wininit.exe", "winlogon.exe")) or
146146
(process.name:"services.exe" and not process.parent.name:"wininit.exe") or
147147
(process.name:"svchost.exe" and not process.parent.name:("MsMpEng.exe", "services.exe", "svchost.exe")) or
148-
(process.name:"spoolsv.exe" and not process.parent.name:"services.exe") or
148+
(process.name:"spoolsv.exe" and not process.parent.name:("services.exe", "Workplace Starter.exe")) or
149149
(process.name:"taskhost.exe" and not process.parent.name:("services.exe", "svchost.exe", "ngentask.exe")) or
150150
(process.name:"taskhostw.exe" and not process.parent.name:("services.exe", "svchost.exe")) or
151-
(process.name:"userinit.exe" and not process.parent.name:("dwm.exe", "winlogon.exe")) or
151+
(process.name:"userinit.exe" and not process.parent.name:("dwm.exe", "winlogon.exe", "KUsrInit.exe")) or
152152
(process.name:("wmiprvse.exe", "wsmprovhost.exe", "winrshost.exe") and not process.parent.name:"svchost.exe") or
153153
/* suspicious child processes */
154-
(process.parent.name:("SearchProtocolHost.exe", "taskhost.exe", "csrss.exe") and not process.name:("werfault.exe", "wermgr.exe", "WerFaultSecure.exe", "conhost.exe")) or
154+
(process.parent.name:("SearchProtocolHost.exe", "taskhost.exe", "csrss.exe") and not process.name:("werfault.exe", "wermgr.exe", "WerFaultSecure.exe", "conhost.exe", "ngentask.exe")) or
155155
(process.parent.name:"autochk.exe" and not process.name:("chkdsk.exe", "doskey.exe", "WerFault.exe")) or
156-
(process.parent.name:"smss.exe" and not process.name:("autochk.exe", "smss.exe", "csrss.exe", "wininit.exe", "winlogon.exe", "setupcl.exe", "WerFault.exe")) or
156+
(process.parent.name:"smss.exe" and not process.name:("autochk.exe", "smss.exe", "csrss.exe", "wininit.exe", "winlogon.exe", "setupcl.exe", "WerFault.exe", "wpbbin.exe", "PvsVmBoot.exe", "SophosNA.exe", "omnissa-ic-nga.exe", "icarus_rvrt.exe", "poqexec.exe")) or
157157
(process.parent.name:"wermgr.exe" and not process.name:("WerFaultSecure.exe", "wermgr.exe", "WerFault.exe")) or
158158
(process.parent.name:"conhost.exe" and not process.name:("mscorsvw.exe", "wermgr.exe", "WerFault.exe", "WerFaultSecure.exe"))
159159
)

0 commit comments

Comments
 (0)