MITRE ATT&CK technique
Inter-Process Communication detection rulesT1559
Inter-Process Communication (T1559) is a MITRE ATT&CK technique in the Execution tactic. This page lists the 6 community-maintained Sigma detection rules in the library mapped to T1559 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
CMSTP Execution Process Access
highDetects various indicators of Microsoft Connection Manager Profile Installer execution
windows · process_access
Trickbot Malware Activity
highDetects Trickbot malware process tree pattern in which "rundll32.exe" is a parent of "wermgr.exe"
windows · process_creation
Dllhost.EXE Initiated Network Connection To Non-Local IP Address
mediumDetects Dllhost.EXE initiating a network connection to a non-local IP address. Aside from Microsoft own IP range that needs to be excluded. Network communication from Dllhost will depend entirely on the hosted DLL. An initial baseline is recommended before deployment.
windows · network_connection
DNS Query Request By Regsvr32.EXE
mediumDetects DNS queries initiated by "Regsvr32.exe"
windows · dns_query
Enable Microsoft Dynamic Data Exchange
mediumEnable Dynamic Data Exchange protocol (DDE) in all supported editions of Microsoft Word or Excel.
windows · registry_set
Network Connection Initiated By Regsvr32.EXE
mediumDetects a network connection initiated by "Regsvr32.exe"
windows · network_connection