Potential Credential Dumping Attempt Using New NetworkProvider - CLI

 Original Source: [Sigma source]
Title: Potential Credential Dumping Attempt Using New NetworkProvider - CLI
Status: test
Description:Detects when an attacker tries to add a new network provider in order to dump clear text credentials, similar to how the NPPSpy tool does it
References:
  -https://learn.microsoft.com/en-us/troubleshoot/windows-client/setup-upgrade-and-drivers/network-provider-settings-removed-in-place-upgrade
  -https://github.com/gtworek/PSBits/tree/master/PasswordStealing/NPPSpy
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-23
modified:2023-02-02
Tags:
  • -'attack.credential-access'
  • -'attack.t1003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -'\System\CurrentControlSet\Services\'
      -'\NetworkProvider'

  condition:selection
Falsepositives:
  -Other legitimate network providers used and not filtred in this rule
Level: high