Potential NTLM Coercion Via Certutil.EXE

 Original Source: [Sigma source]
Title: Potential NTLM Coercion Via Certutil.EXE
Status: test
Description:Detects possible NTLM coercion via certutil using the 'syncwithWU' flag
References:
  -https://github.com/LOLBAS-Project/LOLBAS/issues/243
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-09-01
modified:2023-02-14
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\certutil.exe' OriginalFileName:'CertUtil.exe'   selection_cli:
    CommandLine|contains|all:
      -' -syncwithWU '
      -' \\\\'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high