HackTool - Hydra Password Bruteforce Execution

 Original Source: [Sigma source]
Title: HackTool - Hydra Password Bruteforce Execution
Status: test
Description:Detects command line parameters used by Hydra password guessing hack tool
References:
  -https://github.com/vanhauser-thc/thc-hydra
Author: Vasiliy Burov
Date: 2020-10-05
modified:2023-02-04
Tags:
  • -'attack.credential-access'
  • -'attack.t1110'
  • -'attack.t1110.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -'-u '
      -'-p '

    CommandLine|contains:
      -'^USER^'
      -'^PASS^'

  condition:selection
Falsepositives:
  -Software that uses the caret encased keywords PASS and USER in its command line
Level: high