Sigma Rule Library

Use of Remote.exe

Remote.exe is part of WinDbg in the Windows SDK and can be used for AWL bypass and running remote files.

View on GitHubOpen raw file

Detection logic

selection

- Image|endswith: \remote.exe
- OriginalFileName: remote.exe

Condition

selection

Raw YAML

title: Use of Remote.exe
id: 4eddc365-79b4-43ff-a9d7-99422dc34b93
status: test
description: Remote.exe is part of WinDbg in the Windows SDK and can be used for AWL bypass and running remote files.
references:
    - https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/
    - https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/
author: 'Christopher Peacock @SecurePeacock, SCYTHE @scythe_io'
date: 2022-06-02
tags:
    - attack.execution
    - attack.stealth
    - attack.t1127
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - Image|endswith: '\remote.exe'
        - OriginalFileName: 'remote.exe'
    condition: selection
falsepositives:
    - Approved installs of Windows SDK with Debugging Tools for Windows (WinDbg).
level: medium

False positives

  • Approved installs of Windows SDK with Debugging Tools for Windows (WinDbg).

References

Similar rules