Uncommon Outbound Kerberos Connection

 Original Source: [Sigma source]
Title: Uncommon Outbound Kerberos Connection
Status: test
Description:Detects uncommon outbound network activity via Kerberos default port indicating possible lateral movement or first stage PrivEsc via delegation.
References:
  -https://github.com/GhostPack/Rubeus
Author: Ilyas Ochkov, oscd.community
Date: 2019-10-24
modified:2024-03-15
Tags:
  • -'attack.credential-access'
  • -'attack.t1558'
  • -'attack.lateral-movement'
  • -'attack.t1550.003'
Logsource:
  • category: network_connection
  • product: windows
Detection:
  selection:
    DestinationPort: '88'
    Initiated: 'true'
  filter_main_lsass:
    Image: 'C:\Windows\System32\lsass.exe'
  filter_optional_chrome:
    Image:
      -'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe'
      -'C:\Program Files\Google\Chrome\Application\chrome.exe'

  filter_optional_firefox:
    Image:
      -'C:\Program Files (x86)\Mozilla Firefox\firefox.exe'
      -'C:\Program Files\Mozilla Firefox\firefox.exe'

  filter_optional_tomcat:
    Image|endswith: '\tomcat\bin\tomcat8.exe'
  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Web Browsers and third party application might generate similar activity. An initial baseline is required.
Level: medium