HackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-Secretsdump

 Original Source: [Sigma source]
Title: HackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-Secretsdump
Status: test
Description:Detects default filenames output from the execution of CrackMapExec and Impacket-secretsdump against an endpoint.
References:
  -https://github.com/Porchetta-Industries/CrackMapExec
  -https://github.com/fortra/impacket/blob/ff8c200fd040b04d3b5ff05449646737f836235d/examples/secretsdump.py
Author: SecurityAura
Date: 2022-11-16
modified:2024-06-27
Tags:
  • -'attack.credential-access'
  • -'attack.t1003'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    Image|endswith: '\svchost.exe'
    TargetFilename|re: '\\Windows\\System32\\[a-zA-Z0-9]{8}\.tmp$'
  condition:selection
Falsepositives:
  -Unknown
Level: high