Suspicious Remote Logon with Explicit Credentials

 Original Source: [Sigma source]
Title: Suspicious Remote Logon with Explicit Credentials
Status: test
Description:Detects suspicious processes logging on with explicit credentials
References:
  -https://drive.google.com/file/d/1lKya3_mLnR3UQuCoiYruO3qgu052_iS_/view
Author: oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Tim Shelton
Date: 2020-10-05
modified:2022-08-03
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.initial-access'
  • -'attack.stealth'
  • -'attack.t1078'
  • -'attack.lateral-movement'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '4648'
    ProcessName|endswith:
      -'\cmd.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\winrs.exe'
      -'\wmic.exe'
      -'\net.exe'
      -'\net1.exe'
      -'\reg.exe'

  filter1:
    TargetServerName: 'localhost'
  filter2:
    SubjectUserName|endswith: '$'
    TargetUserName|endswith: '$'
  condition:selection and not 1 of filter*
Falsepositives:
  -Administrators that use the RunAS command or scheduled tasks
Level: medium