This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
New Network Trace Capture Started Via Netsh.EXE
Original Source:
[Sigma source]
Title:
New Network Trace Capture Started Via Netsh.EXE
Status:
test
Description:
Detects the execution of netsh with the "trace" flag in order to start a network capture
References:
-https://blogs.msdn.microsoft.com/canberrapfe/2012/03/30/capture-a-network-trace-without-installing-anything-capture-a-network-trace-of-a-reboot/
-https://klausjochem.me/2016/02/03/netsh-the-cyber-attackers-tool-of-choice/
Author:
Kutepov Anton, oscd.community
Date:
2019-10-24
modified:
2023-02-13
Tags:
-'attack.discovery'
-'attack.credential-access'
-'attack.t1040'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\netsh.exe'
OriginalFileName
:
'netsh.exe'
selection_cli:
CommandLine|contains|all
:
-'trace'
-'start'
condition
:
all of selection_*
Falsepositives:
-Legitimate administration activity
Level:
medium