This rule detects the execution of the RoboForm installer, which may indicate an adversary deploying a credential manager to persist access or harvest stored secrets within the environment. Proactively hunting for this activity allows the SOC team to identify unexpected software installations that could serve as a foothold for credential theft or lateral movement in Azure Sentinel.
rule RoboForm_Installer: PEiD
{
strings:
$a = { 55 8B EC 6A FF 68 E0 F3 40 00 68 44 90 40 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 83 EC 58 53 56 57 89 65 E8 FF 15 68 F0 40 00 33 D2 8A D4 89 15 04 6B 41 00 8B C8 81 E1 FF 00 00 00 89 0D }
condition:
$a at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Scenario: An IT administrator manually deploys the RoboForm MSI package to a workstation via the command line during a standard password manager rollout, triggering the YARA rule on the RoboForm.msi or the temporary installer executable.
C:\Program Files\RoboForm\ directory or specific administrative deployment paths like C:\Temp\Deployments\. Additionally, exclude processes initiated by msiexec.exe with specific administrative arguments or from known deployment service accounts.Scenario: A security team runs a full-disk scan or memory dump analysis using tools like Volatility or YARA scanners that load the RoboForm installer binary into memory or cache it in a temp folder for signature matching, causing the rule to fire on the cached copy.
yara.exe, volatility.exe, splunkforwarder.exe) or paths under C:\Program Files\YARA\ and C:\Tools\Security\.Scenario: A developer or QA engineer installs the RoboForm browser extension or desktop app on a test machine to validate SSO integration, using a custom-built or repackaged installer that retains the original YARA signature but resides in a non-standard development path.
C:\Dev\, C:\Projects\, or C:\Users\<dev_user>\AppData\Local\Temp\ if the user is part of a designated “Development” or “QA” security group.Scenario: A scheduled maintenance job or configuration management agent (e.g., Ansible, Puppet, or SCCM) pushes the RoboForm installer to multiple endpoints simultaneously, resulting