HackTool - RemoteKrbRelay Execution

 Original Source: [Sigma source]
Title: HackTool - RemoteKrbRelay Execution
Status: test
Description:Detects the use of RemoteKrbRelay, a Kerberos relaying tool via CommandLine flags and PE metadata.
References:
  -https://github.com/CICADA8-Research/RemoteKrbRelay
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2024-06-27
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.t1558.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\RemoteKrbRelay.exe' OriginalFileName:'RemoteKrbRelay.exe'   selection_cli_required:
    CommandLine|contains|all:
      -' -clsid '
      -' -target '
      -' -victim '

  selection_cli_attack_smb:
    CommandLine|contains|all:
      -'-smb '
      -'--smbkeyword '

    CommandLine|contains:
      -'interactive'
      -'secrets'
      -'service-add'

  selection_cli_attack_rbcd_main:
    CommandLine|contains: '-rbcd '
  selection_cli_attack_rbcd_options:
    CommandLine|contains:
      -'-cn '
      -'--computername '

  selection_cli_attack_changepass:
    CommandLine|contains: '-chp '
    CommandLine|contains|all:
      -'-chpPass '
      -'-chpUser '

  selection_cli_attack_addgrpname:
    CommandLine|contains|all:
      -'-addgroupmember '
      -'-group '
      -'-groupuser '

  condition:selection_img or selection_cli_required or all of selection_cli_attack_rbcd_* or selection_cli_attack_changepass or selection_cli_attack_addgrpname or selection_cli_attack_smb
Falsepositives:
  -Unlikely
Level: high