This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Capture Credentials with Rpcping.exe
Original Source:
[Sigma source]
Title:
Capture Credentials with Rpcping.exe
Status:
test
Description:
Detects using Rpcping.exe to send a RPC test connection to the target server (-s) and force the NTLM hash to be sent in the process.
References:
-https://lolbas-project.github.io/lolbas/Binaries/Rpcping/
-https://twitter.com/vysecurity/status/974806438316072960
-https://twitter.com/vysecurity/status/873181705024266241
-https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/hh875578(v=ws.11)
Author:
Julia Fomina, oscd.community
Date:
2020-10-09
modified:
2025-10-31
Tags:
-'attack.credential-access'
-'attack.t1003'
Logsource:
category: process_creation
product: windows
Detection:
selection_main_img:
Image|endswith
:
'\RpcPing.exe'
OriginalFileName
:
'\RpcPing.exe'
selection_main_flag:
CommandLine|contains|windash
:
'-s'
selection_cli_ntlm:
CommandLine|contains|windash
:
'-u'
CommandLine|contains
:
'NTLM'
selection_cli_ncacn:
CommandLine|contains|windash
:
'-t'
CommandLine|contains
:
'ncacn_np'
condition
:
all of selection_main_* and 1 of selection_cli_*
Falsepositives:
-Unlikely
Level:
medium