Potential Password Spraying Attempt Using Dsacls.EXE

 Original Source: [Sigma source]
Title: Potential Password Spraying Attempt Using Dsacls.EXE
Status: test
Description:Detects possible password spraying attempts using Dsacls
References:
  -https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/using-dsacls-to-check-ad-object-permissions#password-spraying-anyone
  -https://ss64.com/nt/dsacls.html
  -https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc771151(v=ws.11)
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-06-20
modified:2023-02-04
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\dsacls.exe' OriginalFileName:'DSACLS.EXE'   selection_cli:
    CommandLine|contains|all:
      -'/user:'
      -'/passwd:'

  condition:all of selection*
Falsepositives:
  -Legitimate use of dsacls to bind to an LDAP session
Level: medium