title: Potential BearLPE Exploitation id: 931b6802-d6a6-4267-9ffa-526f57f22aaf status: test description: Detects potential exploitation of the BearLPE exploit using Task Scheduler ".job" import arbitrary DACL write\par references: - https://github.com/djhohnstein/polarbearrepo/blob/f26d3e008093cc5c835e92a7165170baf6713d43/bearlpe/polarbear/polarbear/exploit.cpp author: Olaf Hartong date: 2019-05-22 modified: 2023-01-26 tags: - attack.persistence - attack.execution - attack.privilege-escalation - attack.t1053.005 - car.2013-08-001 - detection.emerging-threats logsource: category: process_creation product: windows detection: selection_img: - Image|endswith: '\schtasks.exe' - OriginalFileName: 'schtasks.exe' selection_cli: CommandLine|contains|all: - '/change' - '/TN' - '/RU' - '/RP' condition: all of selection* falsepositives: - Unknown level: high