WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Load
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects signs of the WMI script host process "scrcons.exe" loading scripting DLLs which could indicates WMI ActiveScriptEventConsumers EventConsumers activity.
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "sa_imageloaded" AND PROCESSNAME endswith "\scrcons.exe" AND OBJECTNAME endswith "\vbscript.dll,\wbemdisp.dll,\wshom.ocx,\scrrun.dll" select Action1.HOSTNAME,Action1.MESSAGE,Action1.PROCESSNAME,Action1.PRODUCT_NAME,Action1.OBJECTNAME
Detection
Execution Mode
realtime
Log Sources
Windows
Author
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)


