Metasploit SMB Authentication

 Original Source: [Sigma source]
Title: Metasploit SMB Authentication
Status: test
Description:Alerts on Metasploit host's authentications on the domain.
References:
  -https://github.com/rapid7/metasploit-framework/blob/1416b5776d963f21b7b5b45d19f3e961201e0aed/lib/rex/proto/smb/client.rb
Author: Chakib Gzenayi (@Chak092), Hosni Mribah
Date: 2020-05-06
modified:2024-01-25
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1021.002'
Logsource:
  • product: windows
  • service: security
Detection:
  selection1:
    EventID:
      -'4625'
      -'4624'

    LogonType: '3'
    AuthenticationPackageName: 'NTLM'
    WorkstationName|re: '^[A-Za-z0-9]{16}$'
  selection2:
    EventID: '4776'
    Workstation|re: '^[A-Za-z0-9]{16}$'
  condition:1 of selection*
Falsepositives:
  -Linux hostnames composed of 16 characters.
Level: high