Capture Credentials with Rpcping.exe

 Original Source: [Sigma source]
Title: Capture Credentials with Rpcping.exe
Status: test
Description:Detects using Rpcping.exe to send a RPC test connection to the target server (-s) and force the NTLM hash to be sent in the process.
References:
  -https://lolbas-project.github.io/lolbas/Binaries/Rpcping/
  -https://twitter.com/vysecurity/status/974806438316072960
  -https://twitter.com/vysecurity/status/873181705024266241
  -https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/hh875578(v=ws.11)
Author: Julia Fomina, oscd.community
Date: 2020-10-09
modified:2025-10-31
Tags:
  • -'attack.credential-access'
  • -'attack.t1003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_main_img:
Image|endswith:'\RpcPing.exe' OriginalFileName:'\RpcPing.exe'   selection_main_flag:
    CommandLine|contains|windash: '-s'
  selection_cli_ntlm:
    CommandLine|contains|windash: '-u'
    CommandLine|contains: 'NTLM'
  selection_cli_ncacn:
    CommandLine|contains|windash: '-t'
    CommandLine|contains: 'ncacn_np'
  condition:all of selection_main_* and 1 of selection_cli_*
Falsepositives:
  -Unlikely
Level: medium