Microsoft IIS Connection Strings Decryption

 Original Source: [Sigma source]
Title: Microsoft IIS Connection Strings Decryption
Status: test
Description:Detects use of aspnet_regiis to decrypt Microsoft IIS connection strings. An attacker with Microsoft IIS web server access via a webshell or alike can decrypt and dump any hardcoded connection strings, such as the MSSQL service account password using aspnet_regiis command.
References:
  -https://www.elastic.co/guide/en/security/current/microsoft-iis-connection-strings-decryption.html
Author: Tim Rauch, Elastic (idea)
Date: 2022-09-28
modified:2022-12-30
Tags:
  • -'attack.credential-access'
  • -'attack.t1003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_name:
Image|endswith:'\aspnet_regiis.exe' OriginalFileName:'aspnet_regiis.exe'   selection_args:
    CommandLine|contains|all:
      -'connectionStrings'
      -' -pdf'

  condition:all of selection*
Falsepositives:
  -Unknown
Level: high