This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential SMB Relay Attack Tool Execution
Original Source:
[Sigma source]
Title:
Potential SMB Relay Attack Tool Execution
Status:
test
Description:
Detects different hacktools used for relay attacks on Windows for privilege escalation
References:
-https://foxglovesecurity.com/2016/09/26/rotten-potato-privilege-escalation-from-service-accounts-to-system/
-https://pentestlab.blog/2017/04/13/hot-potato/
-https://github.com/ohpe/juicy-potato
-https://hunter2.gitbook.io/darthsidious/other/war-stories/domain-admin-in-30-minutes
-https://hunter2.gitbook.io/darthsidious/execution/responder-with-ntlm-relay-and-empire
-https://www.localpotato.com/
Author:
Florian Roth (Nextron Systems)
Date:
2021-07-24
modified:
2023-02-14
Tags:
-'attack.collection'
-'attack.execution'
-'attack.credential-access'
-'attack.t1557.001'
Logsource:
category: process_creation
product: windows
Detection:
selection_pe:
Image|contains
:
-'PetitPotam'
-'RottenPotato'
-'HotPotato'
-'JuicyPotato'
-'\just_dce_'
-'Juicy Potato'
-'\temp\rot.exe'
-'\Potato.exe'
-'\SpoolSample.exe'
-'\Responder.exe'
-'\smbrelayx'
-'\ntlmrelayx'
-'\LocalPotato'
selection_script:
CommandLine|contains
:
-'Invoke-Tater'
-' smbrelay'
-' ntlmrelay'
-'cme smb '
-' /ntlm:NTLMhash '
-'Invoke-PetitPotam'
-'.exe -t * -p '
selection_juicypotato_enum:
CommandLine|contains
:
'.exe -c "{'
CommandLine|endswith
:
'}" -z'
filter_hotpotatoes:
Image|contains
:
-'HotPotatoes6'
-'HotPotatoes7'
-'HotPotatoes '
condition
:
1 of selection_* and not 1 of filter_*
Falsepositives:
-Legitimate files with these rare hacktool names
Level:
critical