Potential SMB Relay Attack Tool Execution

 Original Source: [Sigma source]
Title: Potential SMB Relay Attack Tool Execution
Status: test
Description:Detects different hacktools used for relay attacks on Windows for privilege escalation
References:
  -https://foxglovesecurity.com/2016/09/26/rotten-potato-privilege-escalation-from-service-accounts-to-system/
  -https://pentestlab.blog/2017/04/13/hot-potato/
  -https://github.com/ohpe/juicy-potato
  -https://hunter2.gitbook.io/darthsidious/other/war-stories/domain-admin-in-30-minutes
  -https://hunter2.gitbook.io/darthsidious/execution/responder-with-ntlm-relay-and-empire
  -https://www.localpotato.com/
Author: Florian Roth (Nextron Systems)
Date: 2021-07-24
modified:2023-02-14
Tags:
  • -'attack.collection'
  • -'attack.execution'
  • -'attack.credential-access'
  • -'attack.t1557.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_pe:
    Image|contains:
      -'PetitPotam'
      -'RottenPotato'
      -'HotPotato'
      -'JuicyPotato'
      -'\just_dce_'
      -'Juicy Potato'
      -'\temp\rot.exe'
      -'\Potato.exe'
      -'\SpoolSample.exe'
      -'\Responder.exe'
      -'\smbrelayx'
      -'\ntlmrelayx'
      -'\LocalPotato'

  selection_script:
    CommandLine|contains:
      -'Invoke-Tater'
      -' smbrelay'
      -' ntlmrelay'
      -'cme smb '
      -' /ntlm:NTLMhash '
      -'Invoke-PetitPotam'
      -'.exe -t * -p '

  selection_juicypotato_enum:
    CommandLine|contains: '.exe -c "{'
    CommandLine|endswith: '}" -z'
  filter_hotpotatoes:
    Image|contains:
      -'HotPotatoes6'
      -'HotPotatoes7'
      -'HotPotatoes '

  condition:1 of selection_* and not 1 of filter_*
Falsepositives:
  -Legitimate files with these rare hacktool names
Level: critical