This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - Certipy Execution
Original Source:
[Sigma source]
Title:
HackTool - Certipy Execution
Status:
test
Description:
Detects Certipy execution, a tool for Active Directory Certificate Services enumeration and abuse based on PE metadata characteristics and common command line arguments.
References:
-https://github.com/ly4k/Certipy
-https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-gui-new-authentication-and-request-methods-and-more-7237d88061f7
Author:
pH-T (Nextron Systems), Sittikorn Sangrattanapitak
Date:
2023-04-17
modified:
2024-10-08
Tags:
-'attack.discovery'
-'attack.credential-access'
-'attack.t1649'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\Certipy.exe'
OriginalFileName
:
'Certipy.exe'
Description|contains
:
'Certipy'
selection_cli_commands:
CommandLine|contains
:
-' account '
-' auth '
-' cert '
-' find '
-' forge '
-' ptt '
-' relay '
-' req '
-' shadow '
-' template '
selection_cli_flags:
CommandLine|contains
:
-' -bloodhound'
-' -ca-pfx '
-' -dc-ip '
-' -kirbi'
-' -old-bloodhound'
-' -pfx '
-' -target'
-' -template'
-' -username '
-' -vulnerable'
-'auth -pfx'
-'shadow auto'
-'shadow list'
condition
:
selection_img or all of selection_cli_*
Falsepositives:
-Unlikely
Level:
high