This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - Bloodhound/Sharphound Execution
Original Source:
[Sigma source]
Title:
HackTool - Bloodhound/Sharphound Execution
Status:
test
Description:
Detects command line parameters used by Bloodhound and Sharphound hack tools
References:
-https://github.com/BloodHoundAD/BloodHound
-https://github.com/BloodHoundAD/SharpHound
Author:
Florian Roth (Nextron Systems)
Date:
2019-12-20
modified:
2023-02-04
Tags:
-'attack.discovery'
-'attack.t1087.001'
-'attack.t1087.002'
-'attack.t1482'
-'attack.t1069.001'
-'attack.t1069.002'
-'attack.execution'
-'attack.t1059.001'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Product|contains
:
'SharpHound'
Description|contains
:
'SharpHound'
- Company|contains
:
- 'SpecterOps'
- 'evil corp'
- Image|contains
:
- '\Bloodhound.exe'
- '\SharpHound.exe'
selection_cli_1:
CommandLine|contains
:
-' -CollectionMethod All '
-' --CollectionMethods Session '
-' --Loop --Loopduration '
-' --PortScanTimeout '
-'.exe -c All -d '
-'Invoke-Bloodhound'
-'Get-BloodHoundData'
selection_cli_2:
CommandLine|contains|all
:
-' -JsonFolder '
-' -ZipFileName '
selection_cli_3:
CommandLine|contains|all
:
-' DCOnly '
-' --NoSaveCache '
condition
:
1 of selection_*
Falsepositives:
-Other programs that use these command line option and accepts an 'All' parameter
Level:
high