Esentutl Gather Credentials

 Original Source: [Sigma source]
Title: Esentutl Gather Credentials
Status: test
Description:Conti recommendation to its affiliates to use esentutl to access NTDS dumped file. Trickbot also uses this utilities to get MSEdge info via its module pwgrab.
References:
  -https://twitter.com/vxunderground/status/1423336151860002816
  -https://thedfirreport.com/2021/08/01/bazarcall-to-conti-ransomware-via-trickbot-and-cobalt-strike/
Author: sam0x90
Date: 2021-08-06
modified:2022-10-09
Tags:
  • -'attack.credential-access'
  • -'attack.t1003'
  • -'attack.t1003.003'
  • -'attack.s0404'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -'esentutl'
      -' /p'

  condition:selection
Falsepositives:
  -To be determined
Level: medium