Metasploit Or Impacket Service Installation Via SMB PsExec

 Original Source: [Sigma source]
Title: Metasploit Or Impacket Service Installation Via SMB PsExec
Status: test
Description:Detects usage of Metasploit SMB PsExec (exploit/windows/smb/psexec) and Impacket psexec.py by triggering on specific service installation
References:
  -https://bczyz1.github.io/2021/01/30/psexec.html
Author: Bartlomiej Czyz, Relativity
Date: 2021-01-21
modified:2022-10-05
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1021.002'
  • -'attack.t1570'
  • -'attack.execution'
  • -'attack.t1569.002'
Logsource:
  • product: windows
  • service: security
  • definition: The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697
Detection:
  selection:
    EventID: '4697'
    ServiceFileName|re: '^%systemroot%\\[a-zA-Z]{8}\.exe$'
    ServiceName|re: '(^[a-zA-Z]{4}$)|(^[a-zA-Z]{8}$)|(^[a-zA-Z]{16}$)'
    ServiceStartType: '3'
    ServiceType: '0x10'
  filter:
    ServiceName: 'PSEXESVC'
  condition:selection and not filter
Falsepositives:
  -Possible, different agents with a 8 character binary and a 4, 8 or 16 character service name
Level: high