This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Enumeration for 3rd Party Creds From CLI
Original Source:
[Sigma source]
Title:
Enumeration for 3rd Party Creds From CLI
Status:
test
Description:
Detects processes that query known 3rd party registry keys that holds credentials via commandline
References:
-https://isc.sans.edu/diary/More+Data+Exfiltration/25698
-https://github.com/synacktiv/Radmin3-Password-Cracker/blob/acfc87393e4b7c06353973a14a6c7126a51f36ac/regkey.txt
-https://github.com/HyperSine/how-does-MobaXterm-encrypt-password
-https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#inside-the-registry
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-06-20
modified:
2025-05-22
Tags:
-'attack.credential-access'
-'attack.t1552.002'
Logsource:
category: process_creation
product: windows
Detection:
selection:
CommandLine|contains
:
-'\Software\Aerofox\Foxmail\V3.1'
-'\Software\Aerofox\FoxmailPreview'
-'\Software\DownloadManager\Passwords'
-'\Software\FTPWare\COREFTP\Sites'
-'\Software\IncrediMail\Identities'
-'\Software\Martin Prikryl\WinSCP 2\Sessions'
-'\Software\Mobatek\MobaXterm\'
-'\Software\OpenSSH\Agent\Keys'
-'\Software\OpenVPN-GUI\configs'
-'\Software\ORL\WinVNC3\Password'
-'\Software\Qualcomm\Eudora\CommandLine'
-'\Software\RealVNC\WinVNC4'
-'\Software\RimArts\B2\Settings'
-'\Software\SimonTatham\PuTTY\Sessions'
-'\Software\SimonTatham\PuTTY\SshHostKeys\'
-'\Software\Sota\FFFTP'
-'\Software\TightVNC\Server'
-'\Software\WOW6432Node\Radmin\v3.0\Server\Parameters\Radmin'
filter_main_other_rule:
Image|endswith
:
'reg.exe'
CommandLine|contains
:
-'export'
-'save'
condition
:
selection and not 1 of filter_main_*
Falsepositives:
-Unknown
Level:
medium