Zerologon Exploitation Using Well-known Tools

 Original Source: [Sigma source]
Title: Zerologon Exploitation Using Well-known Tools
Status: stable
Description:This rule is designed to detect attempts to exploit Zerologon (CVE-2020-1472) vulnerability using mimikatz zerologon module or other exploits from machine with "kali" hostname.
References:
  -https://www.secura.com/blog/zero-logon
  -https://bi-zone.medium.com/hunting-for-zerologon-f65c61586382
Author: Demyan Sokolin @_drd0c, Teymur Kheirkhabarov @HeirhabarovT, oscd.community
Date: 2020-10-13
modified:2021-05-30
Tags:
  • -'attack.t1210'
  • -'attack.lateral-movement'
Logsource:
  • service: system
  • product: windows
Detection:
  selection:
    EventID:
      -'5805'
      -'5723'

  keywords:
    - 'kali'
    - 'mimikatz'
  condition:selection and keywords
Falsepositives:
Level: critical