This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
NTDS Exfiltration Filename Patterns
Original Source:
[Sigma source]
Title:
NTDS Exfiltration Filename Patterns
Status:
test
Description:
Detects creation of files with specific name patterns seen used in various tools that export the NTDS.DIT for exfiltration.
References:
-https://github.com/rapid7/metasploit-framework/blob/eb6535009f5fdafa954525687f09294918b5398d/modules/post/windows/gather/ntds_grabber.rb
-https://github.com/rapid7/metasploit-framework/blob/eb6535009f5fdafa954525687f09294918b5398d/data/post/powershell/NTDSgrab.ps1
-https://github.com/SecureAuthCorp/impacket/blob/7d2991d78836b376452ca58b3d14daa61b67cb40/impacket/examples/secretsdump.py#L2405
Author:
Florian Roth (Nextron Systems)
Date:
2022-03-11
modified:
2023-05-05
Tags:
-'attack.credential-access'
-'attack.t1003.003'
Logsource:
product: windows
category: file_event
Detection:
selection:
TargetFilename|endswith
:
-'\All.cab'
-'.ntds.cleartext'
condition
:
selection
Falsepositives:
-Unknown
Level:
high