This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
DCERPC SMB Spoolss Named Pipe
Original Source:
[Sigma source]
Title:
DCERPC SMB Spoolss Named Pipe
Status:
test
Description:
Detects the use of the spoolss named pipe over SMB. This can be used to trigger the authentication via NTLM of any machine that has the spoolservice enabled.
References:
-https://posts.specterops.io/hunting-in-active-directory-unconstrained-delegation-forests-trusts-71f2b33688e1
-https://dirkjanm.io/a-different-way-of-abusing-zerologon/
-https://twitter.com/_dirkjan/status/1309214379003588608
Author:
OTR (Open Threat Research)
Date:
2018-11-28
modified:
2022-08-11
Tags:
-'attack.lateral-movement'
-'attack.t1021.002'
Logsource:
product: windows
service: security
Detection:
selection:
EventID
:
'5145'
ShareName
:
'\\\\\*\\IPC$'
RelativeTargetName
:
'spoolss'
condition
:
selection
Falsepositives:
-Domain Controllers acting as printer servers too? :)
Level:
medium