This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators
Original Source:
[Sigma source]
Title:
HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators
Status:
test
Description:
Detects the creation of file with specific names used by RemoteKrbRelay SMB Relay attack module.
References:
-https://github.com/CICADA8-Research/RemoteKrbRelay/blob/19ec76ba7aa50c2722b23359bc4541c0a9b2611c/Exploit/RemoteKrbRelay/Relay/Attacks/RemoteRegistry.cs#L31-L40
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2024-06-27
modified:
None
Tags:
-'attack.command-and-control'
-'attack.t1219.002'
Logsource:
product: windows
category: file_event
Detection:
selection:
TargetFilename|endswith
:
-':\windows\temp\sam.tmp'
-':\windows\temp\sec.tmp'
-':\windows\temp\sys.tmp'
condition
:
selection
Falsepositives:
-Unlikely
Level:
high