Detect Computer Changed with Anonymous Account: endpointWindowsNoneversion:11
The following analytic detects changes to computer accounts using an anonymous logon.
It leverages Windows Security Event Codes 4742 (Computer Change) with a SubjectUserName of a value "ANONYMOUS LOGON".
This activity can be significant because anonymous logons should not typically be modifying computer accounts, indicating potential unauthorized access or misconfiguration.
If confirmed malicious, this could allow an attacker to alter computer accounts, potentially leading to privilege escalation or persistent access within the network.
Detect Mimikatz Using Loaded Images: endpointWindows2025-02-10version:4
This search looks for reading loaded Images unique to credential dumping with Mimikatz. Deprecated because mimikatz libraries changed and very noisy sysmon Event Code.
Detect Credential Dumping through LSASS access: endpointWindowsNoneversion:16
The following analytic detects attempts to read LSASS memory, indicative of credential dumping.
It leverages Sysmon EventCode 10 and checks for "PROCESS_VM_READ" with query information access on lsass.exe.
Detect Zerologon via Zeek: networkNetworkNoneversion:10
The following analytic detects attempts to exploit the Zerologon CVE-2020-1472 vulnerability via Zeek RPC. It leverages Zeek DCE-RPC data to identify specific operations: NetrServerPasswordSet2, NetrServerReqChallenge, and NetrServerAuthenticate3. This activity is significant because it indicates an attempt to gain unauthorized access to a domain controller, potentially leading to a complete takeover of an organization's IT infrastructure. If confirmed malicious, the impact could be severe, including data theft, ransomware deployment, or other devastating outcomes. Immediate investigation of the identified IP addresses and RPC operations is crucial.
Windows Possible Credential Dumping: endpointEndpointNoneversion:15
The following analytic detects possible credential dumping by identifying suspicious process access to LSASS with credential-dumping-related call traces.
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_QUERY_LIMITED_INFORMATION (0x1000) and PROCESS_DUP_HANDLE (0x40).