This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - CrackMapExec Execution
Original Source:
[Sigma source]
Title:
HackTool - CrackMapExec Execution
Status:
test
Description:
This rule detect common flag combinations used by CrackMapExec in order to detect its use even if the binary has been replaced.
References:
-https://mpgn.gitbook.io/crackmapexec/smb-protocol/authentication/checking-credentials-local
-https://www.mandiant.com/resources/telegram-malware-iranian-espionage
-https://www.infosecmatter.com/crackmapexec-module-library/?cmem=mssql-mimikatz
-https://www.infosecmatter.com/crackmapexec-module-library/?cmem=smb-pe_inject
Author:
Florian Roth (Nextron Systems)
Date:
2022-02-25
modified:
2023-03-08
Tags:
-'attack.execution'
-'attack.persistence'
-'attack.privilege-escalation'
-'attack.credential-access'
-'attack.discovery'
-'attack.t1047'
-'attack.t1053'
-'attack.t1059.003'
-'attack.t1059.001'
-'attack.t1110'
-'attack.t1201'
Logsource:
category: process_creation
product: windows
Detection:
selection_binary:
Image|endswith
:
'\crackmapexec.exe'
selection_special:
CommandLine|contains
:
' -M pe_inject '
selection_execute:
CommandLine|contains|all
:
-' --local-auth'
-' -u '
-' -x '
selection_hash:
CommandLine|contains|all
:
-' --local-auth'
-' -u '
-' -p '
-' -H 'NTHASH''
selection_module_mssql:
CommandLine|contains|all
:
-' mssql '
-' -u '
-' -p '
-' -M '
-' -d '
selection_module_smb1:
CommandLine|contains|all
:
-' smb '
-' -u '
-' -H '
-' -M '
-' -o '
selection_module_smb2:
CommandLine|contains|all
:
-' smb '
-' -u '
-' -p '
-' --local-auth'
part_localauth_1:
CommandLine|contains|all
:
-' --local-auth'
-' -u '
-' -p '
part_localauth_2:
CommandLine|contains|all
:
-' 10.'
-' 192.168.'
-'/24 '
condition
:
1 of selection_* or all of part_localauth*
Falsepositives:
-Unknown
Level:
high