This hunt hypothesis targets the execution of a specific lightweight process identified by the PKLITEv100c1 YARA signature to detect potential early-stage adversary activity or benign utility usage that may evade standard detection logic. Proactively hunting for this indicator in Azure Sentinel is essential to validate its behavior across endpoints, ensuring that low-severity signals are not overlooked as false positives while establishing a baseline for future anomaly detection.
rule PKLITEv100c1
{
meta:
author="malware-lu"
strings:
$a0 = { 2E 8C 1E [2] 8B 1E [2] 8C DA 81 C2 [2] 3B DA 72 ?? 81 EB [2] 83 EB ?? FA 8E D3 BC [2] FB FD BE [2] 8B FE }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the PKLITEv100c1 detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Scenario: Microsoft Office Click-to-Run Updates
OfficeClickToRun.exe process frequently spawns temporary instances of pkLite.exe (or similar packaging tools) during background updates to install new language packs or feature modules. This is a standard behavior for the Microsoft 365 app suite.C:\Program Files\Microsoft Office Root\Office16\ and the process name contains “ClickToRun” or “PkLite”. Alternatively, whitelist the specific SHA256 hash of the known good Microsoft packaging binary.Scenario: SCCM (ConfigMgr) Application Deployment
pkLite.exe to unpack and install software packages on endpoints, particularly when deploying custom MSI or CAB-based applications.ccmexec.exe (the SCCM client service) where the command line arguments contain keywords like /deploy, /install, or specific application IDs used in your deployment catalog.Scenario: Antivirus Real-Time Scanning of Temporary Folders
pkLite.exe as a helper utility to scan temporary download folders (%TEMP%) or quarantine directories. This triggers the rule when users download large archives that require unpacking before full scanning.