HackTool - SharpLdapWhoami Execution

 Original Source: [Sigma source]
Title: HackTool - SharpLdapWhoami Execution
Status: test
Description:Detects SharpLdapWhoami, a whoami alternative that queries the LDAP service on a domain controller
References:
  -https://github.com/bugch3ck/SharpLdapWhoami
Author: Florian Roth (Nextron Systems)
Date: 2022-08-29
modified:2023-02-04
Tags:
  • -'attack.discovery'
  • -'attack.t1033'
  • -'car.2016-03-001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_name:
    Image|endswith: '\SharpLdapWhoami.exe'
  selection_pe:
OriginalFileName|contains:'SharpLdapWhoami' Product:'SharpLdapWhoami'   selection_flags1:
    CommandLine|endswith:
      -' /method:ntlm'
      -' /method:kerb'
      -' /method:nego'
      -' /m:nego'
      -' /m:ntlm'
      -' /m:kerb'

  condition:1 of selection*
Falsepositives:
  -Programs that use the same command line flags
Level: high