Suspicious Group And Account Reconnaissance Activity Using Net.EXE

 Original Source: [Sigma source]
Title: Suspicious Group And Account Reconnaissance Activity Using Net.EXE
Status: test
Description:Detects suspicious reconnaissance command line activity on Windows systems using Net.EXE Check if the user that executed the commands is suspicious (e.g. service accounts, LOCAL_SYSTEM)
References:
  -https://redcanary.com/blog/how-one-hospital-thwarted-a-ryuk-ransomware-outbreak/
  -https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/
  -https://research.nccgroup.com/2022/08/19/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack/
Author: Florian Roth (Nextron Systems), omkar72, @svch0st, Nasreddine Bencherchali (Nextron Systems)
Date: 2019-01-16
modified:2023-03-02
Tags:
  • -'attack.discovery'
  • -'attack.t1087.001'
  • -'attack.t1087.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\net.exe'
      - '\net1.exe'
    - OriginalFileName:
      - 'net.exe'
      - 'net1.exe'
  selection_group_root:
    CommandLine|contains:
      -' group '
      -' localgroup '

  selection_group_flags:
    CommandLine|contains:
      -'domain admins'
      -' administrator'
      -' administrateur'
      -'enterprise admins'
      -'Exchange Trusted Subsystem'
      -'Remote Desktop Users'
      -'Utilisateurs du Bureau à distance'
      -'Usuarios de escritorio remoto'
      -' /do'

  filter_group_add:
    CommandLine|contains: ' /add'
  selection_accounts_root:
    CommandLine|contains: ' accounts '
  selection_accounts_flags:
    CommandLine|contains: ' /do'
  condition:selection_img and ((all of selection_group_* and not filter_group_add) or all of selection_accounts_*)
Falsepositives:
  -Inventory tool runs
  -Administrative activity
Level: medium