// soc investigation 2026-12-07
SOC316 SyncAppvPublishingServer Execution to Bypass Powershell Restriction
letsdefend Medium ✓ true positive
mitre/T1110mitre/T1059-001mitre/T1548-002mitre/T1136-001mitre/T1098mitre/T1216-002
analyst verdict TRUE POSITIVE
✓

Alert Details

FieldValue
RuleSOC316 - SyncAppvPublishingServer Execution to Bypass PowerShell Restriction
HostAdler
IP172.16.17.117
TimeAug 27, 2024 07:51 AM
SeverityMedium
Device ActionAllowed
VerdictTrue Positive - Malicious

Attack Chain

07:50 — Successful brute force login targeting user letsdefend from 138.199.53.248

07:51 — Attacker ran initial recon: whoami, whoami /groups

07:51 — LOLBin execution via wscript.exe (parent: cmd.exe):

C:\windows\system32\SyncAppvPublishingServer.vbs \n;Start-Process powershell -Verb RunAs

07:51 — UAC elevation succeeded; attacker obtained elevated PowerShell session

07:52 — Rogue local user Letssdefend created and added to Administrators group via New-LocalUser / Add-LocalGroupMember

07:52 — Administrator password reset:

net user Administrator P@ssw0rd!

Post-incident — Endpoint contained


MITRE ATT&CK

Technique IDTacticTechnique
T1110Credential AccessBrute Force
T1059.001ExecutionCommand and Scripting Interpreter: PowerShell
T1216.002Defense EvasionSystem Script Proxy Execution: SyncAppvPublishingServer
T1548.002Privilege EscalationAbuse Elevation Control Mechanism: Bypass UAC
T1136.001PersistenceCreate Account: Local Account
T1098PersistenceAccount Manipulation

Note: LetsDefend platform mapped T1216 (parent). Independent mapping confirmed T1216.002 (SyncAppvPublishingServer sub-technique). Platform maps defense evasion broadly — T1216.002 is the precise technique.


IOCs

TypeValueNotes
IP138.199.53.248Attacker — Romanian VPN, brute force history
IP172.16.17.117Victim host — Adler
UsernameletsdefendBrute forced account
UsernameLetssdefendRogue admin account created by attacker
Processwscript.exeLOLBin launcher
ScriptSyncAppvPublishingServer.vbsAbused MS system script

Analysis Reports