HackTool - Typical HiveNightmare SAM File Export

 Original Source: [Sigma source]
Title: HackTool - Typical HiveNightmare SAM File Export
Status: test
Description:Detects files written by the different tools that exploit HiveNightmare
References:
  -https://github.com/GossiTheDog/HiveNightmare
  -https://github.com/FireFart/hivenightmare/
  -https://github.com/WiredPulse/Invoke-HiveNightmare
  -https://twitter.com/cube0x0/status/1418920190759378944
Author: Florian Roth (Nextron Systems)
Date: 2021-07-23
modified:2024-06-27
Tags:
  • -'attack.credential-access'
  • -'attack.t1552.001'
  • -'cve.2021-36934'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    - TargetFilename|contains:
      - '\hive_sam_'
      - '\SAM-2021-'
      - '\SAM-2022-'
      - '\SAM-2023-'
      - '\SAM-haxx'
      - '\Sam.save'
TargetFilename:'C:\windows\temp\sam'   condition:selection
Falsepositives:
  -Files that accidentally contain these strings
Level: high