This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - Potential Impacket Lateral Movement Activity
Original Source:
[Sigma source]
Title:
HackTool - Potential Impacket Lateral Movement Activity
Status:
stable
Description:
Detects wmiexec/dcomexec/atexec/smbexec from Impacket framework
References:
-https://github.com/SecureAuthCorp/impacket/blob/8b1a99f7c715702eafe3f24851817bb64721b156/examples/wmiexec.py
-https://github.com/SecureAuthCorp/impacket/blob/8b1a99f7c715702eafe3f24851817bb64721b156/examples/atexec.py
-https://github.com/SecureAuthCorp/impacket/blob/8b1a99f7c715702eafe3f24851817bb64721b156/examples/smbexec.py
-https://github.com/SecureAuthCorp/impacket/blob/8b1a99f7c715702eafe3f24851817bb64721b156/examples/dcomexec.py
-https://www.elastic.co/guide/en/security/current/suspicious-cmd-execution-via-wmi.html
Author:
Ecco, oscd.community, Jonhnathan Ribeiro, Tim Rauch
Date:
2019-09-03
modified:
2023-02-21
Tags:
-'attack.execution'
-'attack.t1047'
-'attack.lateral-movement'
-'attack.t1021.003'
Logsource:
category: process_creation
product: windows
Detection:
selection_other:
ParentImage|endswith
:
-'\wmiprvse.exe'
-'\mmc.exe'
-'\explorer.exe'
-'\services.exe'
CommandLine|contains|all
:
-'cmd.exe'
-'/Q'
-'/c'
-'\\\\127.0.0.1\\'
-'&1'
selection_atexec:
ParentCommandLine|contains
:
-'svchost.exe -k netsvcs'
-'taskeng.exe'
CommandLine|contains|all
:
-'cmd.exe'
-'/C'
-'Windows\Temp\'
-'&1'
condition
:
1 of selection_*
Falsepositives:
-Unknown
Level:
high