This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Microsoft IIS Service Account Password Dumped
Original Source:
[Sigma source]
Title:
Microsoft IIS Service Account Password Dumped
Status:
test
Description:
Detects the Internet Information Services (IIS) command-line tool, AppCmd, being used to list passwords
References:
-https://www.elastic.co/guide/en/security/current/microsoft-iis-service-account-password-dumped.html
-https://twitter.com/0gtweet/status/1588815661085917186?cxt=HHwWhIDUyaDbzYwsAAAA
-https://www.netspi.com/blog/technical/network-penetration-testing/decrypting-iis-passwords-to-break-out-of-the-dmz-part-2/
Author:
Tim Rauch, Janantha Marasinghe, Elastic (original idea)
Date:
2022-11-08
modified:
2023-01-22
Tags:
-'attack.credential-access'
-'attack.t1003'
Logsource:
category: process_creation
product: windows
Detection:
selection_base_name:
Image|endswith
:
'\appcmd.exe'
OriginalFileName
:
'appcmd.exe'
selection_base_list:
CommandLine|contains
:
'list '
selection_standalone:
CommandLine|contains
:
-' /config'
-' /xml'
-' -config'
-' -xml'
selection_cmd_flags:
CommandLine|contains
:
-' /@t'
-' /text'
-' /show'
-' -@t'
-' -text'
-' -show'
selection_cmd_grep:
CommandLine|contains
:
-':\*'
-'password'
condition
:
all of selection_base_* and (selection_standalone or all of selection_cmd_*)
Falsepositives:
-Unknown
Level:
high