Successful Overpass the Hash Attempt

 Original Source: [Sigma source]
Title: Successful Overpass the Hash Attempt
Status: test
Description:Detects successful logon with logon type 9 (NewCredentials) which matches the Overpass the Hash behavior of e.g Mimikatz's sekurlsa::pth module.
References:
  -https://web.archive.org/web/20220419045003/https://cyberwardog.blogspot.com/2017/04/chronicles-of-threat-hunter-hunting-for.html
Author: Roberto Rodriguez (source), Dominik Schaudel (rule)
Date: 2018-02-12
modified:2021-11-27
Tags:
  • -'attack.lateral-movement'
  • -'attack.s0002'
  • -'attack.t1550.002'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '4624'
    LogonType: '9'
    LogonProcessName: 'seclogo'
    AuthenticationPackageName: 'Negotiate'
  condition:selection
Falsepositives:
  -Runas command-line tool using /netonly parameter
Level: high