External Remote SMB Logon from Public IP

 Original Source: [Sigma source]
Title: External Remote SMB Logon from Public IP
Status: test
Description:Detects successful logon from public IP address via SMB. This can indicate a publicly-exposed SMB port.
References:
  -https://www.inversecos.com/2020/04/successful-4624-anonymous-logons-to.html
  -https://twitter.com/Purp1eW0lf/status/1616144561965002752
Author: Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity)
Date: 2023-01-19
modified:2024-03-11
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.initial-access'
  • -'attack.credential-access'
  • -'attack.stealth'
  • -'attack.t1133'
  • -'attack.t1078'
  • -'attack.t1110'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '4624'
    LogonType: '3'
  filter_main_local_ranges:
    IpAddress|cidr:
      -'::1/128'
      -'10.0.0.0/8'
      -'127.0.0.0/8'
      -'172.16.0.0/12'
      -'192.168.0.0/16'
      -'169.254.0.0/16'
      -'fc00::/7'
      -'fe80::/10'

  filter_main_empty:
    IpAddress: '-'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Legitimate or intentional inbound connections from public IP addresses on the SMB port.
Level: high