EXPLORE
← Back to Explore
sigmamediumHunting

Uncommon Assistive Technology Applications Execution Via AtBroker.EXE

Detects the start of a non built-in assistive technology applications via "Atbroker.EXE".

MITRE ATT&CK

defense-evasion

Detection Query

selection_img:
  - Image|endswith: \AtBroker.exe
  - OriginalFileName: AtBroker.exe
selection_cli:
  CommandLine|contains: start
filter_main_builtin:
  CommandLine|contains:
    - animations
    - audiodescription
    - caretbrowsing
    - caretwidth
    - colorfiltering
    - cursorindicator
    - cursorscheme
    - filterkeys
    - focusborderheight
    - focusborderwidth
    - highcontrast
    - keyboardcues
    - keyboardpref
    - livecaptions
    - magnifierpane
    - messageduration
    - minimumhitradius
    - mousekeys
    - Narrator
    - osk
    - overlappedcontent
    - showsounds
    - soundsentry
    - speechreco
    - stickykeys
    - togglekeys
    - voiceaccess
    - windowarranging
    - windowtracking
    - windowtrackingtimeout
    - windowtrackingzorder
filter_optional_java:
  CommandLine|contains: Oracle_JavaAccessBridge
condition: all of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*

Author

Mateusz Wydra, oscd.community

Created

2020-10-12

Data Sources

windowsProcess Creation Events

Platforms

windows

Tags

attack.defense-evasionattack.t1218
Raw Content
title: Uncommon  Assistive Technology Applications Execution Via AtBroker.EXE
id: f24bcaea-0cd1-11eb-adc1-0242ac120002
status: test
description: Detects the start of a non built-in assistive technology applications via "Atbroker.EXE".
references:
    - http://www.hexacorn.com/blog/2016/07/22/beyond-good-ol-run-key-part-42/
    - https://lolbas-project.github.io/lolbas/Binaries/Atbroker/
author: Mateusz Wydra, oscd.community
date: 2020-10-12
modified: 2024-03-06
tags:
    - attack.defense-evasion
    - attack.t1218
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        - Image|endswith: '\AtBroker.exe'
        - OriginalFileName: 'AtBroker.exe'
    selection_cli:
        CommandLine|contains: 'start'
    filter_main_builtin:
        CommandLine|contains:
            - 'animations'
            - 'audiodescription'
            - 'caretbrowsing'
            - 'caretwidth'
            - 'colorfiltering'
            - 'cursorindicator'
            - 'cursorscheme'
            - 'filterkeys'
            - 'focusborderheight'
            - 'focusborderwidth'
            - 'highcontrast'
            - 'keyboardcues'
            - 'keyboardpref'
            - 'livecaptions'
            - 'magnifierpane'
            - 'messageduration'
            - 'minimumhitradius'
            - 'mousekeys'
            - 'Narrator'
            - 'osk'
            - 'overlappedcontent'
            - 'showsounds'
            - 'soundsentry'
            - 'speechreco'
            - 'stickykeys'
            - 'togglekeys'
            - 'voiceaccess'
            - 'windowarranging'
            - 'windowtracking'
            - 'windowtrackingtimeout'
            - 'windowtrackingzorder'
    filter_optional_java:
        CommandLine|contains: 'Oracle_JavaAccessBridge'
    condition: all of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
    - Legitimate, non-default assistive technology applications execution
level: medium