PUA - PingCastle Execution From Potentially Suspicious Parent

 Original Source: [Sigma source]
Title: PUA - PingCastle Execution From Potentially Suspicious Parent
Status: test
Description:Detects the execution of PingCastle, a tool designed to quickly assess the Active Directory security level via a script located in a potentially suspicious or uncommon location.
References:
  -https://github.com/vletoux/pingcastle
  -https://thedfirreport.com/2023/10/30/netsupport-intrusion-results-in-domain-compromise/
  -https://github.com/fengjixuchui/Start-ADEnum/blob/e237a739db98b6104427d833004836507da36a58/Functions/Start-ADEnum.ps1#L450
  -https://github.com/lkys37en/Start-ADEnum/blob/5b42c54215fe5f57fc59abc52c20487d15764005/Functions/Start-ADEnum.ps1#L680
  -https://github.com/projectHULK/AD_Recon/blob/dde2daba9b3393a9388cbebda87068972cc0bd3b/SecurityAssessment.ps1#L2699
  -https://github.com/802-1x/Compliance/blob/2e53df8b6e89686a0b91116b3f42c8f717dca820/Ping%20Castle/Get-PingCastle-HTMLComplianceReport.ps1#L8
  -https://github.com/EvotecIT/TheDashboard/blob/481a9ce8f82f2fd55fe65220ee6486bae6df0c9d/Examples/RunReports/PingCastle.ps1
Author: Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems)
Date: 2024-01-11
modified:None
Tags:
  • -'attack.reconnaissance'
  • -'attack.t1595'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_parent_ext:
    ParentCommandLine|contains:
      -'.bat'
      -'.chm'
      -'.cmd'
      -'.hta'
      -'.htm'
      -'.html'
      -'.js'
      -'.lnk'
      -'.ps1'
      -'.vbe'
      -'.vbs'
      -'.wsf'

  selection_parent_path_1:
    ParentCommandLine|contains:
      -':\Perflogs\'
      -':\Temp\'
      -':\Users\Public\'
      -':\Windows\Temp\'
      -'\AppData\Local\Temp'
      -'\AppData\Roaming\'
      -'\Temporary Internet'

  selection_parent_path_2:
    - ParentCommandLine|contains|all:
      - ':\Users\'
      - '\Favorites\'
    - ParentCommandLine|contains|all:
      - ':\Users\'
      - '\Favourites\'
    - ParentCommandLine|contains|all:
      - ':\Users\'
      - '\Contacts\'
  selection_cli:
Image|endswith:'\PingCastle.exe' OriginalFileName:'PingCastle.exe' Product:'Ping Castle'     - CommandLine|contains:
      - '--scanner aclcheck'
      - '--scanner antivirus'
      - '--scanner computerversion'
      - '--scanner foreignusers'
      - '--scanner laps_bitlocker'
      - '--scanner localadmin'
      - '--scanner nullsession'
      - '--scanner nullsession-trust'
      - '--scanner oxidbindings'
      - '--scanner remote'
      - '--scanner share'
      - '--scanner smb'
      - '--scanner smb3querynetwork'
      - '--scanner spooler'
      - '--scanner startup'
      - '--scanner zerologon'
CommandLine|contains:'--no-enum-limit'     - CommandLine|contains|all:
      - '--healthcheck'
      - '--level Full'
    - CommandLine|contains|all:
      - '--healthcheck'
      - '--server '
  condition:1 of selection_parent_* and selection_parent_ext and selection_cli
Falsepositives:
  -Unknown
Level: high