This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - CrackMapExec File Indicators
Original Source:
[Sigma source]
Title:
HackTool - CrackMapExec File Indicators
Status:
test
Description:
Detects file creation events with filename patterns used by CrackMapExec.
References:
-https://github.com/byt3bl33d3r/CrackMapExec/
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2024-03-11
modified:
2024-06-27
Tags:
-'attack.credential-access'
-'attack.t1003.001'
Logsource:
product: windows
category: file_event
Detection:
selection_path:
TargetFilename|startswith
:
'C:\Windows\Temp\'
selection_names_str:
TargetFilename|endswith
:
-'\temp.ps1'
-'\msol.ps1'
selection_names_re:
TargetFilename|re
:
'\\[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}\.txt$'
TargetFilename|re
:
'\\[a-zA-Z]{8}\.tmp$'
condition
:
selection_path and 1 of selection_names_*
Falsepositives:
-Unknown
Level:
high