Name:Rubeus Kerberos Ticket Exports Through Winlogon Access id:5ed8c50a-8869-11ec-876f-acde48001122 version:15 date:None author:Mauricio Velazco, Splunk status:production type:TTP Description:The following analytic detects an uncommon process requesting full access rights to winlogon.exe, which may indicate Rubeus exporting Kerberos tickets from memory.
It leverages Sysmon EventCode 10 and checks for full-access rights, specifically the value 0x1f3fff. Data_source:
-Sysmon EventID 10
search:`sysmon` EventCode=10 TargetImage="*:\\Windows\\system32\\winlogon.exe" NOT SourceImage IN ( "C:\\Windows\\system32\\LogonUI.exe", "C:\\Windows\\system32\\lsass.exe", "C:\\Windows\\system32\\smss.exe", "C:\\Windows\\system32\\svchost.exe", "C:\\Windows\\system32\\wbem\\wmiprvse.exe" )
``` Convert GrantedAccess from hexadecimal to decimal. 0x1f3fff is the legacy full-access mask observed for this activity. ``` | eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16) | eval PROCESS_ALL_ACCESS_LEGACY = 2047999 | eval legacy_full_access_set = bit_and(g_access_decimal, PROCESS_ALL_ACCESS_LEGACY) | where legacy_full_access_set == PROCESS_ALL_ACCESS_LEGACY
| stats count min(_time) as firstTime max(_time) as lastTime BY user_id dest signature_id signature granted_access Opcode SourceImage SourceProcessGUID SourceProcessId TargetImage TargetProcessGUID TargetProcessId CallTrace vendor_product
how_to_implement:This search needs Sysmon Logs and a sysmon configuration, which includes EventCode 10. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. known_false_positives:No false positives have been identified at this time. References: -https://github.com/GhostPack/Rubeus -https://web.archive.org/web/20210725005734/http://www.harmj0y.net/blog/redteaming/from-kekeo-to-rubeus/ -https://attack.mitre.org/techniques/T1550/003/ drilldown_searches: name:'View the detection results for - "$dest$"' search:'%original_detection_search% | search dest = "$dest$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$dest$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['CISA AA23-347A', 'Active Directory Kerberos Attacks', 'BlackSuit Ransomware', 'Scattered Lapsus$ Hunters', 'ZOVWiper']