Suspicious Computer Machine Password by PowerShell

 Original Source: [Sigma source]
Title: Suspicious Computer Machine Password by PowerShell
Status: test
Description:The Reset-ComputerMachinePassword cmdlet changes the computer account password that the computers use to authenticate to the domain controllers in the domain. You can use it to reset the password of the local computer.
References:
  -https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/reset-computermachinepassword?view=powershell-5.1
  -https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/
Author: frack113
Date: 2022-02-21
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.initial-access'
  • -'attack.stealth'
  • -'attack.t1078'
Logsource:
  • product: windows
  • category: ps_module
  • definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
Detection:
  selection:
    ContextInfo|contains: 'Reset-ComputerMachinePassword'
  condition:selection
Falsepositives:
  -Administrator PowerShell scripts
Level: medium