This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - SharpView Execution
Original Source:
[Sigma source]
Title:
HackTool - SharpView Execution
Status:
test
Description:
Adversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
References:
-https://github.com/tevora-threat/SharpView/
-https://github.com/PowerShellMafia/PowerSploit/blob/d943001a7defb5e0d1657085a77a0e78609be58f/Recon/PowerView.ps1
-https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1049/T1049.md#atomic-test-4---system-discovery-using-sharpview
Author:
frack113
Date:
2021-12-10
modified:
2023-02-14
Tags:
-'attack.discovery'
-'attack.t1049'
-'attack.t1069.002'
-'attack.t1482'
-'attack.t1135'
-'attack.t1033'
Logsource:
category: process_creation
product: windows
Detection:
selection:
OriginalFileName
:
'SharpView.exe'
Image|endswith
:
'\SharpView.exe'
- CommandLine|contains
:
- 'Add-RemoteConnection'
- 'Convert-ADName'
- 'ConvertFrom-SID'
- 'ConvertFrom-UACValue'
- 'Convert-SidToName'
- 'Export-PowerViewCSV'
- 'Find-DomainObjectPropertyOutlier'
- 'Find-DomainProcess'
- 'Find-DomainShare'
- 'Find-DomainUserEvent'
- 'Find-DomainUserLocation'
- 'Find-ForeignGroup'
- 'Find-ForeignUser'
- 'Find-GPOComputerAdmin'
- 'Find-GPOLocation'
- 'Find-Interesting'
- 'Find-LocalAdminAccess'
- 'Find-ManagedSecurityGroups'
- 'Get-CachedRDPConnection'
- 'Get-DFSshare'
- 'Get-DomainComputer'
- 'Get-DomainController'
- 'Get-DomainDFSShare'
- 'Get-DomainDNSRecord'
- 'Get-DomainFileServer'
- 'Get-DomainForeign'
- 'Get-DomainGPO'
- 'Get-DomainGroup'
- 'Get-DomainGUIDMap'
- 'Get-DomainManagedSecurityGroup'
- 'Get-DomainObject'
- 'Get-DomainOU'
- 'Get-DomainPolicy'
- 'Get-DomainSID'
- 'Get-DomainSite'
- 'Get-DomainSPNTicket'
- 'Get-DomainSubnet'
- 'Get-DomainTrust'
- 'Get-DomainUserEvent'
- 'Get-ForestDomain'
- 'Get-ForestGlobalCatalog'
- 'Get-ForestTrust'
- 'Get-GptTmpl'
- 'Get-GroupsXML'
- 'Get-LastLoggedOn'
- 'Get-LoggedOnLocal'
- 'Get-NetComputer'
- 'Get-NetDomain'
- 'Get-NetFileServer'
- 'Get-NetForest'
- 'Get-NetGPO'
- 'Get-NetGroupMember'
- 'Get-NetLocalGroup'
- 'Get-NetLoggedon'
- 'Get-NetOU'
- 'Get-NetProcess'
- 'Get-NetRDPSession'
- 'Get-NetSession'
- 'Get-NetShare'
- 'Get-NetSite'
- 'Get-NetSubnet'
- 'Get-NetUser'
- 'Get-PathAcl'
- 'Get-PrincipalContext'
- 'Get-RegistryMountedDrive'
- 'Get-RegLoggedOn'
- 'Get-WMIRegCachedRDPConnection'
- 'Get-WMIRegLastLoggedOn'
- 'Get-WMIRegMountedDrive'
- 'Get-WMIRegProxy'
- 'Invoke-ACLScanner'
- 'Invoke-CheckLocalAdminAccess'
- 'Invoke-Kerberoast'
- 'Invoke-MapDomainTrust'
- 'Invoke-RevertToSelf'
- 'Invoke-Sharefinder'
- 'Invoke-UserImpersonation'
- 'Remove-DomainObjectAcl'
- 'Remove-RemoteConnection'
- 'Request-SPNTicket'
- 'Set-DomainObject'
- 'Test-AdminAccess'
condition
:
selection
Falsepositives:
-Unknown
Level:
high