{"id":"7f2376f9-42ee-4dfc-9360-fecff9a88fc8","title":"BitLockerTogo.EXE Execution","description":"Detects the execution of \"BitLockerToGo.EXE\".\nBitLocker To Go is BitLocker Drive Encryption on removable data drives. This feature includes the encryption of, USB flash drives, SD cards, External hard disk drives, Other drives that are formatted by using the NTFS, FAT16, FAT32, or exFAT file system.\nThis is a rarely used application and usage of it at all is worth investigating.\nMalware such as Lumma stealer has been seen using this process as a target for process hollowing.\n","author":"Josh Nickels, mttaggart","status":"test","level":"low","date":"2024-07-11","modified":"","tags":["attack.stealth","attack.t1218"],"technique_ids":["T1218"],"logsource":{"category":"process_creation","product":"windows"},"falsepositives":["Legitimate usage of BitLockerToGo.exe to encrypt portable devices."],"references":["https://tria.ge/240521-ynezpagf56/behavioral1","https://any.run/report/6eea2773c1b4b5c6fb7c142933e220c96f9a4ec89055bf0cf54accdcde7df535/a407f006-ee45-420d-b576-f259094df091","https://bazaar.abuse.ch/sample/8c75f8e94486f5bbf461505823f5779f328c5b37f1387c18791e0c21f3fdd576/","https://bazaar.abuse.ch/sample/64e6605496919cd76554915cbed88e56fdec10dec6523918a631754664b8c8d3/"],"source_path":"rules/windows/process_creation/proc_creation_win_bitlockertogo_execution.yml","source_sha256":"b00c8fcc1460bedc25d8d54f578eaf3fe4aa365495fae65759eb977ec172d592","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_bitlockertogo_execution.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: BitLockerTogo.EXE Execution\nid: 7f2376f9-42ee-4dfc-9360-fecff9a88fc8\nstatus: test\ndescription: |\n    Detects the execution of \"BitLockerToGo.EXE\".\n    BitLocker To Go is BitLocker Drive Encryption on removable data drives. This feature includes the encryption of, USB flash drives, SD cards, External hard disk drives, Other drives that are formatted by using the NTFS, FAT16, FAT32, or exFAT file system.\n    This is a rarely used application and usage of it at all is worth investigating.\n    Malware such as Lumma stealer has been seen using this process as a target for process hollowing.\nreferences:\n    - https://tria.ge/240521-ynezpagf56/behavioral1\n    - https://any.run/report/6eea2773c1b4b5c6fb7c142933e220c96f9a4ec89055bf0cf54accdcde7df535/a407f006-ee45-420d-b576-f259094df091\n    - https://bazaar.abuse.ch/sample/8c75f8e94486f5bbf461505823f5779f328c5b37f1387c18791e0c21f3fdd576/\n    - https://bazaar.abuse.ch/sample/64e6605496919cd76554915cbed88e56fdec10dec6523918a631754664b8c8d3/\nauthor: Josh Nickels, mttaggart\ndate: 2024-07-11\ntags:\n    - attack.stealth\n    - attack.t1218\nlogsource:\n    category: process_creation\n    product: windows\ndetection:\n    selection:\n        Image|endswith: '\\BitLockerToGo.exe'\n    condition: selection\nfalsepositives:\n    - Legitimate usage of BitLockerToGo.exe to encrypt portable devices.\nlevel: low\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1218","id":"T1218","name":"System Binary Proxy Execution","page":"techniques/enterprise/T1218/"}],"data_path":"data/detection-rules/7f2376f9-42ee-4dfc-9360-fecff9a88fc8.json","kind":"sigma"}
