This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - SOAPHound Execution
Original Source:
[Sigma source]
Title:
HackTool - SOAPHound Execution
Status:
test
Description:
Detects the execution of SOAPHound, a .NET tool for collecting Active Directory data, using specific command-line arguments that may indicate an attempt to extract sensitive AD information.
References:
-https://github.com/FalconForceTeam/SOAPHound
-https://medium.com/falconforce/soaphound-tool-to-collect-active-directory-data-via-adws-165aca78288c
Author:
@kostastsale
Date:
2024-01-26
modified:
None
Tags:
-'attack.discovery'
-'attack.t1087'
Logsource:
product: windows
category: process_creation
Detection:
selection_1:
CommandLine|contains
:
-' --buildcache '
-' --bhdump '
-' --certdump '
-' --dnsdump '
selection_2:
CommandLine|contains
:
-' -c '
-' --cachefilename '
-' -o '
-' --outputdirectory'
condition
:
all of selection_*
Falsepositives:
-Unknown
Level:
high