This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Remote Logon with Explicit Credentials
Original Source:
[Sigma source]
Title:
Suspicious Remote Logon with Explicit Credentials
Status:
test
Description:
Detects suspicious processes logging on with explicit credentials
References:
-https://drive.google.com/file/d/1lKya3_mLnR3UQuCoiYruO3qgu052_iS_/view
Author:
oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Tim Shelton
Date:
2020-10-05
modified:
2022-08-03
Tags:
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.initial-access'
-'attack.stealth'
-'attack.t1078'
-'attack.lateral-movement'
Logsource:
product: windows
service: security
Detection:
selection:
EventID
:
'4648'
ProcessName|endswith
:
-'\cmd.exe'
-'\powershell.exe'
-'\pwsh.exe'
-'\winrs.exe'
-'\wmic.exe'
-'\net.exe'
-'\net1.exe'
-'\reg.exe'
filter1:
TargetServerName
:
'localhost'
filter2:
SubjectUserName|endswith
:
'$'
TargetUserName|endswith
:
'$'
condition
:
selection and not 1 of filter*
Falsepositives:
-Administrators that use the RunAS command or scheduled tasks
Level:
medium