This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-Secretsdump
Original Source:
[Sigma source]
Title:
HackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-Secretsdump
Status:
test
Description:
Detects default filenames output from the execution of CrackMapExec and Impacket-secretsdump against an endpoint.
References:
-https://github.com/Porchetta-Industries/CrackMapExec
-https://github.com/fortra/impacket/blob/ff8c200fd040b04d3b5ff05449646737f836235d/examples/secretsdump.py
Author:
SecurityAura
Date:
2022-11-16
modified:
2024-06-27
Tags:
-'attack.credential-access'
-'attack.t1003'
Logsource:
product: windows
category: file_event
Detection:
selection:
Image|endswith
:
'\svchost.exe'
TargetFilename|re
:
'\\Windows\\System32\\[a-zA-Z0-9]{8}\.tmp$'
condition
:
selection
Falsepositives:
-Unknown
Level:
high