diff --git a/detections/endpoint/ssa___windows_mshta_child_process.yml b/detections/endpoint/ssa___windows_mshta_child_process.yml index 3e1373264e..2d102c2bc4 100644 --- a/detections/endpoint/ssa___windows_mshta_child_process.yml +++ b/detections/endpoint/ssa___windows_mshta_child_process.yml @@ -1,6 +1,6 @@ name: Windows MSHTA Child Process id: f63f7e9c-9526-11ec-9fc7-acde48001122 -version: 1 +version: 2 date: '2022-02-23' author: Michael Haag, Splunk type: TTP @@ -14,10 +14,10 @@ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + null), parent_process_name=lower(ucast(map_get(input_event, "parent_process_name"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND parent_process_name IS NOT - NULL | where parent_process_name="mshta.exe" AND ( process_name="powershell.exe" OR + NULL | where like(parent_process_name, "%\\\\mshta.exe") AND ( process_name="powershell.exe" OR process_name="cmd.exe" OR process_name="scrcons.exe" OR process_name="colorcpl.exe" OR process_name="msbuild.exe" OR process_name="microsoft.workflow.compiler.exe" OR process_name="searchprotocolhost.exe" OR process_name="cscript.exe" OR process_name="wscript.exe")