HackTool - Certipy Execution

 Original Source: [Sigma source]
Title: HackTool - Certipy Execution
Status: test
Description:Detects Certipy execution, a tool for Active Directory Certificate Services enumeration and abuse based on PE metadata characteristics and common command line arguments.
References:
  -https://github.com/ly4k/Certipy
  -https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-gui-new-authentication-and-request-methods-and-more-7237d88061f7
Author: pH-T (Nextron Systems), Sittikorn Sangrattanapitak
Date: 2023-04-17
modified:2024-10-08
Tags:
  • -'attack.discovery'
  • -'attack.credential-access'
  • -'attack.t1649'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\Certipy.exe' OriginalFileName:'Certipy.exe' Description|contains:'Certipy'   selection_cli_commands:
    CommandLine|contains:
      -' account '
      -' auth '
      -' cert '
      -' find '
      -' forge '
      -' ptt '
      -' relay '
      -' req '
      -' shadow '
      -' template '

  selection_cli_flags:
    CommandLine|contains:
      -' -bloodhound'
      -' -ca-pfx '
      -' -dc-ip '
      -' -kirbi'
      -' -old-bloodhound'
      -' -pfx '
      -' -target'
      -' -template'
      -' -username '
      -' -vulnerable'
      -'auth -pfx'
      -'shadow auto'
      -'shadow list'

  condition:selection_img or all of selection_cli_*
Falsepositives:
  -Unlikely
Level: high