Title:New or Renamed User Account with '$' Character Status:test Description:Detects the creation of a user with the "$" character. This can be used by attackers to hide a user or trick detection systems that lack the parsing mechanisms.
References: -https://twitter.com/SBousseaden/status/1387743867663958021 Author: Ilyas Ochkov, oscd.community Date: 2019-10-25 modified:2024-01-16 Tags:
-'attack.stealth'
-'attack.t1036'
Logsource:
product: windows
service: security
Detection: selection_create: EventID:
'4720' SamAccountName|contains:
'$' selection_rename: EventID:
'4781' NewTargetUserName|contains:
'$' filter_main_homegroup: EventID:
'4720' TargetUserName:
'HomeGroupUser$' condition:1 of selection_* and not 1 of filter_main_* Falsepositives:
-Unknown Level:medium