This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Weak Encryption Enabled and Kerberoast
Original Source:
[Sigma source]
Title:
Weak Encryption Enabled and Kerberoast
Status:
test
Description:
Detects scenario where weak encryption is enabled for a user profile which could be used for hash/password cracking.
References:
-https://adsecurity.org/?p=2053
-https://blog.harmj0y.net/redteaming/another-word-on-delegation/
Author:
@neu5ron
Date:
2017-07-30
modified:
2021-11-27
Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
product: windows
service: security
definition: Requirements: Audit Policy : Account Management > Audit User Account Management, Group Policy : Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Account Management\Audit User Account Management
Detection:
selection:
EventID
:
'4738'
olduac_des:
OldUacValue|endswith
:
-'8???'
-'9???'
-'A???'
-'B???'
-'C???'
-'D???'
-'E???'
-'F???'
newuac_des:
NewUacValue|endswith
:
-'8???'
-'9???'
-'A???'
-'B???'
-'C???'
-'D???'
-'E???'
-'F???'
olduac_preauth:
OldUacValue|endswith
:
-'1????'
-'3????'
-'5????'
-'7????'
-'9????'
-'B????'
-'D????'
-'F????'
newuac_preauth:
NewUacValue|endswith
:
-'1????'
-'3????'
-'5????'
-'7????'
-'9????'
-'B????'
-'D????'
-'F????'
olduac_encrypted:
OldUacValue|endswith
:
-'8??'
-'9??'
-'A??'
-'B??'
-'C??'
-'D??'
-'E??'
-'F??'
newuac_encrypted:
NewUacValue|endswith
:
-'8??'
-'9??'
-'A??'
-'B??'
-'C??'
-'D??'
-'E??'
-'F??'
condition
:
selection and ((newuac_des and not olduac_des) or (newuac_preauth and not olduac_preauth) or (newuac_encrypted and not olduac_encrypted))
Falsepositives:
-Unknown
Level:
high