Potential Credential Dumping Attempt Using New NetworkProvider - REG

 Original Source: [Sigma source]
Title: Potential Credential Dumping Attempt Using New NetworkProvider - REG
Status: test
Description:Detects when an attacker tries to add a new network provider in order to dump clear text credentials, similar to how the NPPSpy tool does it
References:
  -https://learn.microsoft.com/en-us/troubleshoot/windows-client/setup-upgrade-and-drivers/network-provider-settings-removed-in-place-upgrade
  -https://github.com/gtworek/PSBits/tree/master/PasswordStealing/NPPSpy
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-23
modified:2023-08-17
Tags:
  • -'attack.credential-access'
  • -'attack.t1003'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|contains|all:
      -'\System\CurrentControlSet\Services\'
      -'\NetworkProvider'

  filter:
    TargetObject|contains:
      -'\System\CurrentControlSet\Services\WebClient\NetworkProvider'
      -'\System\CurrentControlSet\Services\LanmanWorkstation\NetworkProvider'
      -'\System\CurrentControlSet\Services\RDPNP\NetworkProvider'

  filter_valid_procs:
    Image: 'C:\Windows\System32\poqexec.exe'
  condition:selection and not 1 of filter*
Falsepositives:
  -Other legitimate network providers used and not filtred in this rule
Level: medium