Sigma Rule Library

SyncAppvPublishingServer Execution to Bypass Powershell Restriction

Detects SyncAppvPublishingServer process execution which usually utilized by adversaries to bypass PowerShell execution restrictions.

View on GitHubOpen raw file

Detection logic

selection

ScriptBlockText|contains: SyncAppvPublishingServer.exe

Condition

selection

Raw YAML

title: SyncAppvPublishingServer Execution to Bypass Powershell Restriction
id: dddfebae-c46f-439c-af7a-fdb6bde90218
related:
    - id: fde7929d-8beb-4a4c-b922-be9974671667
      type: derived
    - id: 9f7aa113-9da6-4a8d-907c-5f1a4b908299
      type: derived
status: test
description: Detects SyncAppvPublishingServer process execution which usually utilized by adversaries to bypass PowerShell execution restrictions.
references:
    - https://lolbas-project.github.io/lolbas/Binaries/Syncappvpublishingserver/
author: 'Ensar Şamil, @sblmsrsn, OSCD Community'
date: 2020-10-05
modified: 2022-12-25
tags:
    - attack.stealth
    - attack.t1218
logsource:
    product: windows
    category: ps_script
    definition: 'Requirements: Script Block Logging must be enabled'
detection:
    selection:
        ScriptBlockText|contains: 'SyncAppvPublishingServer.exe'
    condition: selection
falsepositives:
    - App-V clients
level: medium

False positives

  • App-V clients

References

  • derivedfde7929d-8beb-4a4c-b922-be9974671667
  • derived9f7aa113-9da6-4a8d-907c-5f1a4b908299

Similar rules