This rule detects the execution of RSCs Process Patcher, a utility often used by adversaries to modify process attributes or hide malicious processes from standard monitoring tools. Proactively hunting for this activity in Azure Sentinel allows the SOC to identify potential process injection or anti-forensic techniques that may precede more complex post-exploitation actions.
rule RSCs_Process_Patcher_v151: PEiD
{
strings:
$a = { 68 00 20 40 00 E8 C3 01 00 00 80 38 00 74 0D 66 81 78 FE 22 20 75 02 EB 03 40 EB EE 8B F8 B8 04 60 40 00 68 C4 20 40 00 68 D4 20 40 00 6A 00 6A 00 6A 04 6A 00 6A 00 6A 00 57 50 E8 9F 01 00 00 85 C0 0F 84 39 01 00 00 BE 00 60 40 00 8B 06 A3 28 21 40 00 83 }
$b = { 68 00 20 40 00 E8 C3 01 00 00 80 38 00 74 0D 66 81 78 FE 22 20 75 02 EB 03 40 EB EE 8B F8 B8 04 60 40 00 68 C4 20 40 00 68 D4 20 40 00 6A 00 6A 00 6A 04 6A 00 6A 00 6A 00 57 50 E8 9F 01 00 00 85 C0 0F 84 39 01 00 00 BE 00 60 40 00 8B 06 A3 28 21 40 00 83 C6 40 83 7E FC 00 0F 84 8F 00 00 00 8B 3E 83 C6 04 85 FF 0F 84 E5 00 00 00 81 FF 72 21 73 63 74 7A 0F B7 1E 8B CF 8D 7E 02 C7 05 24 21 40 00 00 00 00 00 83 05 24 21 40 00 01 50 A1 28 21 40 00 39 05 24 21 40 00 58 0F 84 D8 00 00 00 60 6A 00 53 68 2C 21 40 00 51 FF 35 C4 20 40 00 E8 0A 01 00 00 61 60 FC BE 2C 21 40 00 8B CB F3 A6 61 75 C2 03 FB 60 E8 3E 00 00 00 6A 00 53 57 51 FF 35 C4 20 40 00 E8 FB 00 00 00 85 C0 0F 84 A2 00 00 00 61 03 FB 8B F7 E9 71 FF FF FF 60 FF 35 C8 20 40 00 E8 CB 00 00 00 61 C7 05 }
condition:
for any of ($*) : ( $ at pe.entry_point )
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Scenario: A DevOps engineer runs the dotnet CLI to build a .NET Core application that includes a NuGet package containing a native C++ library. The build process invokes msbuild or csc.exe, which may spawn child processes or load specific DLLs that match the heuristic signature of the “Process Patcher” if the rule targets generic patching behaviors or specific memory structures.
dotnet.exe, msbuild.exe, or csc.exe and the working directory is under a known build artifact path (e.g., C:\src\, C:\build\, or *.sln project directories).Scenario: An IT administrator uses Sysinternals Process Monitor or Process Explorer to troubleshoot application hangs. These tools often inject into processes or read memory sections to analyze handles and threads, which can trigger YARA rules looking for process injection or patching patterns.
procmon.exe, procexp.exe, or procmon64.exe and the user is a member of the Domain Admins or IT Support group.Scenario: A scheduled task runs Windows Update or a third-party patch management agent like WSUS or SCCM Client. During the installation phase, these agents may temporarily patch system DLLs or modify process memory to apply hotfixes, potentially matching the “Process Patcher” signature if the rule is broad.
wuauclt.exe, TrustedInstaller.exe, or CCMExec.exe and the execution time falls within the defined maintenance window (e.g., 02:00–04:00 AM