This rule targets the specific execution of the “Alex Protector” tool, a utility often used by threat actors to manage process protection or evade standard monitoring mechanisms. Proactively hunting for this signature allows the SOC to identify potential footholds or post-exploitation activities that may be leveraging this tool to maintain persistence or obscure malicious processes within the Azure environment.
rule Alex_Protector_v04_beta_1_by_Alex: PEiD
{
strings:
$a = { 60 E8 01 00 00 00 C7 83 C4 04 33 C9 E8 01 00 00 00 68 83 C4 04 E8 01 00 00 00 68 83 C4 04 B9 ?? 00 00 00 E8 01 00 00 00 68 83 C4 04 E8 00 00 00 00 E8 01 00 00 00 C7 83 C4 04 8B 2C 24 83 C4 04 E8 01 00 00 00 A9 83 C4 04 81 ED 3C 13 40 00 E8 01 00 00 00 68 }
$b = { 60 E8 01 00 00 00 C7 83 C4 04 33 C9 E8 01 00 00 00 68 83 C4 04 E8 01 00 00 00 68 83 C4 04 B9 ?? 00 00 00 E8 01 00 00 00 68 83 C4 04 E8 00 00 00 00 E8 01 00 00 00 C7 83 C4 04 8B 2C 24 83 C4 04 E8 01 00 00 00 A9 83 C4 04 81 ED 3C 13 40 00 E8 01 00 00 00 68 83 C4 04 E8 00 00 00 00 E8 00 00 00 00 49 E8 01 00 00 00 68 83 C4 04 85 C9 75 DF E8 B9 02 00 00 E8 01 00 00 00 C7 83 C4 04 8D 95 63 14 40 00 E8 01 00 00 00 C7 83 C4 04 90 90 90 E8 CA 01 00 00 01 02 03 04 05 68 90 60 8B 74 24 24 8B 7C 24 28 FC B2 80 33 DB A4 B3 02 E8 6D 00 00 00 73 F6 33 C9 E8 64 00 00 00 73 1C 33 C0 E8 5B 00 00 00 73 23 B3 02 41 B0 10 E8 4F 00 00 00 12 C0 73 F7 75 3F AA EB D4 E8 4D 00 00 00 2B CB 75 10 E8 42 00 00 00 EB 28 AC D1 E8 74 4D 13 C9 EB 1C 91 48 C1 E0 08 AC E8 2C 00 00 00 3D 00 }
condition:
for any of ($*) : ( $ at pe.entry_point )
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Scenario: Automated Backup Verification via PowerShell
Get-ChildItem or Test-Path on specific directories (e.g., C:\Backup\Daily) in a loop, which may match the pattern if the rule targets specific path strings or file enumeration behaviors.CommandLine contains -Backup or -Verify and the parent process is vssadmin.exe or wbadmin.exe. Alternatively, exclude if the script path resides under C:\Program Files\Veeam\ or C:\Windows\Logs\WindowsBackup\.Scenario: Endpoint Detection & Response (EDR) Telemetry Collection
NtQuerySystemInformation with SystemProcessInformation) or file path patterns associated with common application directories, these legitimate telemetry threads can trigger the rule.Image ends with falconctl.exe, cb.exe, or sentineloneagent.exe. Additionally, exclude if the thread name contains Telemetry, Collector, or Sensor.Scenario: Scheduled Log Rotation and Cleanup Jobs
cmd.exe /c del or PowerShell Remove-Item on specific directories (