Windows Terminal settings.json modified by an uncommon command-line process

Alerts on Windows Terminal settings.json changes made by an uncommon command-line or script host process.

FreeUnreviewedSigmamediumv1
title: Windows Terminal settings.json modified by an uncommon command-line process
id: 831cd67a-7419-4f3c-b1f6-d4e7eade31a9
status: test
description: This rule flags file creation or modification of Windows Terminal's settings.json located under the Microsoft.WindowsTerminal LocalState path when the action is performed by a less common executable (such as cmd.exe, PowerShell, wscript, cscript, or mshta). Attackers may abuse these utilities to persist by changing terminal behavior or tooling configuration. It relies on Windows file event telemetry that captures the process image performing the write and the target filename being modified.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/74438b0237d141ee9c99747976447dc884cb1a39/atomics/T1547.015/T1547.015.md#atomic-test-1---persistence-by-modifying-windows-terminal-profile
  - https://twitter.com/nas_bench/status/1550836225652686848
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_susp_windows_terminal_profile.yml
author: frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-07-22
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.t1547.015
logsource:
  product: windows
  category: file_event
detection:
  selection:
    Image|endswith:
      - \cmd.exe
      - \cscript.exe
      - \mshta.exe
      - \powershell.exe
      - \pwsh.exe
      - \wscript.exe
    TargetFilename|endswith: \AppData\Local\Packages\Microsoft.WindowsTerminal_8wekyb3d8bbwe\LocalState\settings.json
  condition: selection
falsepositives:
  - Some false positives may occur with admin scripts that set WT settings.
level: medium
license: DRL-1.1
related:
  - id: 9b64de98-9db3-4033-bd7a-f51430105f00
    type: derived

What it detects

This rule flags file creation or modification of Windows Terminal's settings.json located under the Microsoft.WindowsTerminal LocalState path when the action is performed by a less common executable (such as cmd.exe, PowerShell, wscript, cscript, or mshta). Attackers may abuse these utilities to persist by changing terminal behavior or tooling configuration. It relies on Windows file event telemetry that captures the process image performing the write and the target filename being modified.

Known false positives

  • Some false positives may occur with admin scripts that set WT settings.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.