This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
PUA - PingCastle Execution From Potentially Suspicious Parent
Original Source:
[Sigma source]
Title:
PUA - PingCastle Execution From Potentially Suspicious Parent
Status:
test
Description:
Detects the execution of PingCastle, a tool designed to quickly assess the Active Directory security level via a script located in a potentially suspicious or uncommon location.
References:
-https://github.com/vletoux/pingcastle
-https://thedfirreport.com/2023/10/30/netsupport-intrusion-results-in-domain-compromise/
-https://github.com/fengjixuchui/Start-ADEnum/blob/e237a739db98b6104427d833004836507da36a58/Functions/Start-ADEnum.ps1#L450
-https://github.com/lkys37en/Start-ADEnum/blob/5b42c54215fe5f57fc59abc52c20487d15764005/Functions/Start-ADEnum.ps1#L680
-https://github.com/projectHULK/AD_Recon/blob/dde2daba9b3393a9388cbebda87068972cc0bd3b/SecurityAssessment.ps1#L2699
-https://github.com/802-1x/Compliance/blob/2e53df8b6e89686a0b91116b3f42c8f717dca820/Ping%20Castle/Get-PingCastle-HTMLComplianceReport.ps1#L8
-https://github.com/EvotecIT/TheDashboard/blob/481a9ce8f82f2fd55fe65220ee6486bae6df0c9d/Examples/RunReports/PingCastle.ps1
Author:
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems)
Date:
2024-01-11
modified:
None
Tags:
-'attack.reconnaissance'
-'attack.t1595'
Logsource:
category: process_creation
product: windows
Detection:
selection_parent_ext:
ParentCommandLine|contains
:
-'.bat'
-'.chm'
-'.cmd'
-'.hta'
-'.htm'
-'.html'
-'.js'
-'.lnk'
-'.ps1'
-'.vbe'
-'.vbs'
-'.wsf'
selection_parent_path_1:
ParentCommandLine|contains
:
-':\Perflogs\'
-':\Temp\'
-':\Users\Public\'
-':\Windows\Temp\'
-'\AppData\Local\Temp'
-'\AppData\Roaming\'
-'\Temporary Internet'
selection_parent_path_2:
- ParentCommandLine|contains|all
:
- ':\Users\'
- '\Favorites\'
- ParentCommandLine|contains|all
:
- ':\Users\'
- '\Favourites\'
- ParentCommandLine|contains|all
:
- ':\Users\'
- '\Contacts\'
selection_cli:
Image|endswith
:
'\PingCastle.exe'
OriginalFileName
:
'PingCastle.exe'
Product
:
'Ping Castle'
- CommandLine|contains
:
- '--scanner aclcheck'
- '--scanner antivirus'
- '--scanner computerversion'
- '--scanner foreignusers'
- '--scanner laps_bitlocker'
- '--scanner localadmin'
- '--scanner nullsession'
- '--scanner nullsession-trust'
- '--scanner oxidbindings'
- '--scanner remote'
- '--scanner share'
- '--scanner smb'
- '--scanner smb3querynetwork'
- '--scanner spooler'
- '--scanner startup'
- '--scanner zerologon'
CommandLine|contains
:
'--no-enum-limit'
- CommandLine|contains|all
:
- '--healthcheck'
- '--level Full'
- CommandLine|contains|all
:
- '--healthcheck'
- '--server '
condition
:
1 of selection_parent_* and selection_parent_ext and selection_cli
Falsepositives:
-Unknown
Level:
high