HackTool - Potential Impacket Lateral Movement Activity

 Original Source: [Sigma source]
Title: HackTool - Potential Impacket Lateral Movement Activity
Status: stable
Description:Detects wmiexec/dcomexec/atexec/smbexec from Impacket framework
References:
  -https://github.com/SecureAuthCorp/impacket/blob/8b1a99f7c715702eafe3f24851817bb64721b156/examples/wmiexec.py
  -https://github.com/SecureAuthCorp/impacket/blob/8b1a99f7c715702eafe3f24851817bb64721b156/examples/atexec.py
  -https://github.com/SecureAuthCorp/impacket/blob/8b1a99f7c715702eafe3f24851817bb64721b156/examples/smbexec.py
  -https://github.com/SecureAuthCorp/impacket/blob/8b1a99f7c715702eafe3f24851817bb64721b156/examples/dcomexec.py
  -https://www.elastic.co/guide/en/security/current/suspicious-cmd-execution-via-wmi.html
Author: Ecco, oscd.community, Jonhnathan Ribeiro, Tim Rauch
Date: 2019-09-03
modified:2023-02-21
Tags:
  • -'attack.execution'
  • -'attack.t1047'
  • -'attack.lateral-movement'
  • -'attack.t1021.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_other:
    ParentImage|endswith:
      -'\wmiprvse.exe'
      -'\mmc.exe'
      -'\explorer.exe'
      -'\services.exe'

    CommandLine|contains|all:
      -'cmd.exe'
      -'/Q'
      -'/c'
      -'\\\\127.0.0.1\\'
      -'&1'

  selection_atexec:
    ParentCommandLine|contains:
      -'svchost.exe -k netsvcs'
      -'taskeng.exe'

    CommandLine|contains|all:
      -'cmd.exe'
      -'/C'
      -'Windows\Temp\'
      -'&1'

  condition:1 of selection_*
Falsepositives:
  -Unknown
Level: high