heroui logo

Lure-Themed Internet-Delivered RMM Executable

Elastic Detection Rules

View Source
Summary
Identifies Windows-endpoint executions where an Internet-delivered remote management tool (RMM) is disguised as a document, invitation, or another company product. The rule correlates between file creation events with a non-null origin_url and process-start events for known RMM signers, including a broad allowlist of legitimate RMM publishers. It normalizes and links provenance between the file event and the process event, including an optional same-path file-origin fallback when origin URL is not available. A built-in ES|QL prompt classifies the lure semantics into one of three categories (LURE, PRODUCT_ALIGNED, AMBIGUOUS) and only LURE results are emitted. The detection relies on two provenance branches: (1) file-origin evidence (origin_url stripped of Zone.Identifier) and (2) process-origin evidence (publisher/signature match against a curated list). The rule applies a strict precedence in linguistic classification of the filename, focusing on whether the filename claims a meaningfully unrelated product, content, or brand to distinguish a lure from a legitimate RMM artifact. If a direct web origin exists or a same-path file-origin fallback is established, it favors an explanation of lure deployment via social-engineering tactics. Outputs include critical fields such as timestamp, host, user, process details, file/process hashes, origins, and provenance references for investigation. The rule maps to MITRE ATT&CK techniques: T1204 (User Execution), T1036 (Masquerading), and T1219 (Remote Access Tools). It uses Elastic Defend data with ES|QL completion via a Claude Sonnet 4.6 model to produce a single-line classification, and only LURE results are kept for alerting and investigation. The rule is designed for Elastic Cloud deployments with ES|QL and LLM integration, and includes a detailed triage guide for investigators to validate provenance, classify semantic claims of the lure, and determine the appropriate response and remediation steps.
Categories
  • Endpoint
  • Windows
Data Sources
  • File
  • Process
ATT&CK Techniques
  • T1204
  • T1204.002
  • T1036
  • T1219
  • T1219.002
Created: 2026-09-24