| Field | Value |
|---|---|
| Rule | SOC316 - SyncAppvPublishingServer Execution to Bypass PowerShell Restriction |
| Host | Adler |
| IP | 172.16.17.117 |
| Time | Aug 27, 2024 07:51 AM |
| Severity | Medium |
| Device Action | Allowed |
| Verdict | True Positive - Malicious |
07:50 — Successful brute force login targeting user letsdefend from 138.199.53.248
07:51 — Attacker ran initial recon: whoami, whoami /groups
07:51 — LOLBin execution via wscript.exe (parent: cmd.exe):
C:\windows\system32\SyncAppvPublishingServer.vbs \n;Start-Process powershell -Verb RunAs
07:51 — UAC elevation succeeded; attacker obtained elevated PowerShell session
07:52 — Rogue local user Letssdefend created and added to Administrators group via New-LocalUser / Add-LocalGroupMember
07:52 — Administrator password reset:
net user Administrator P@ssw0rd!
Post-incident — Endpoint contained
| Technique ID | Tactic | Technique |
|---|---|---|
| T1110 | Credential Access | Brute Force |
| T1059.001 | Execution | Command and Scripting Interpreter: PowerShell |
| T1216.002 | Defense Evasion | System Script Proxy Execution: SyncAppvPublishingServer |
| T1548.002 | Privilege Escalation | Abuse Elevation Control Mechanism: Bypass UAC |
| T1136.001 | Persistence | Create Account: Local Account |
| T1098 | Persistence | Account Manipulation |
Note: LetsDefend platform mapped T1216 (parent). Independent mapping confirmed T1216.002 (SyncAppvPublishingServer sub-technique). Platform maps defense evasion broadly — T1216.002 is the precise technique.
| Type | Value | Notes |
|---|---|---|
| IP | 138.199.53.248 | Attacker — Romanian VPN, brute force history |
| IP | 172.16.17.117 | Victim host — Adler |
| Username | letsdefend | Brute forced account |
| Username | Letssdefend | Rogue admin account created by attacker |
| Process | wscript.exe | LOLBin launcher |
| Script | SyncAppvPublishingServer.vbs | Abused MS system script |