This detection identifies potential malicious activity where adversaries leverage Just-In-Time (JIT) policies to install software or execute commands within Azure environments, often mimicking legitimate administrative actions. The SOC team should proactively hunt for this behavior in Azure Sentinel to validate JIT session legitimacy and uncover stealthy lateral movement that may bypass standard static access controls.
rule Thinstall2736Jitit
{
meta:
author="malware-lu"
strings:
$a0 = { 9C 60 E8 00 00 00 00 58 BB F3 1C 00 00 2B C3 50 68 00 00 40 00 68 00 26 00 00 68 CC 00 00 00 E8 C1 FE FF FF E9 97 FF FF FF CC CC CC CC CC CC CC CC CC CC CC 55 8B EC 83 C4 F4 FC 53 57 56 8B 75 08 8B 7D 0C C7 45 FC 08 00 00 00 33 DB BA 00 00 00 80 43 33 C0 E8 19 01 00 00 73 0E 8B 4D F8 E8 27 01 00 00 02 45 F7 AA EB E9 E8 04 01 00 00 0F 82 96 00 00 00 E8 F9 00 00 00 73 5B B9 04 00 00 00 E8 05 01 00 00 48 74 DE 0F 89 C6 00 00 00 E8 DF 00 00 00 73 1B 55 BD 00 01 00 00 E8 DF 00 00 00 88 07 47 4D 75 F5 E8 C7 00 00 00 72 E9 5D EB A2 B9 01 00 00 00 E8 D0 00 00 00 83 C0 07 89 45 F8 C6 45 F7 00 83 F8 08 74 89 E8 B1 00 00 00 88 45 F7 E9 7C FF FF FF B9 07 00 00 00 E8 AA 00 00 00 50 33 C9 B1 02 E8 A0 00 00 00 8B C8 41 41 58 0B C0 74 04 8B D8 EB 5E 83 F9 02 74 6A 41 E8 88 00 00 00 89 45 FC E9 48 FF FF FF E8 87 00 00 00 49 E2 09 8B C3 E8 7D 00 00 00 EB 3A 49 8B C1 55 8B 4D FC 8B E8 33 C0 D3 E5 E8 5D 00 00 00 0B C5 5D 8B D8 E8 5F 00 00 00 3D 00 00 01 00 73 14 3D FF 37 00 00 73 0E 3D 7F 02 00 00 73 08 83 F8 7F 77 04 41 41 41 41 56 8B F7 2B F0 F3 A4 5E E9 F0 FE FF FF 33 C0 EB 05 8B C7 2B 45 0C 5E 5F 5B C9 C2 08 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Thinstall2736Jitit detection rule, tailored to a legitimate enterprise environment:
Scenario: Automated Patch Deployment via Microsoft Endpoint Configuration Manager (SCCM)
ccmsetup.exe) frequently executes Just-In-Time (JIT) compilation tasks or installs updates that trigger the Thinstall2736 signature when running in a JIT context. This often occurs during scheduled maintenance windows where mass software deployments are active.C:\Program Files\Microsoft Configuration Manager\AdminConsole\bin\ or specifically filter for the parent process name ccmsetup.exe.Scenario: Scheduled Antivirus Definition Updates (CrowdStrike Falcon)
csfalcon.exe) performs background JIT compilation of its own heuristic modules during daily definition updates. This internal activity mimics the installation behavior detected by the rule, particularly when the sensor is updating its local policy engine.csfalcon.exe and the specific user context SYSTEM, as these updates typically run under the system account rather than a standard interactive user.Scenario: Office 365 ProPlus Click-to-Run Updates
OfficeClickToRun.exe) dynamically installs or patches components (e.g., Excel add-ins) using JIT compilation techniques to minimize downtime. This is a common occurrence in enterprise environments where Office is updated continuously without user intervention.OfficeClickToRun.exe when the command line contains arguments related to “Update” or “Install”, specifically focusing on the path `C:\Program Files