Title:Zerologon Exploitation Using Well-known Tools Status:stable Description:This rule is designed to detect attempts to exploit Zerologon (CVE-2020-1472) vulnerability using mimikatz zerologon module or other exploits from machine with "kali" hostname. References: -https://www.secura.com/blog/zero-logon -https://bi-zone.medium.com/hunting-for-zerologon-f65c61586382 Author: Demyan Sokolin @_drd0c, Teymur Kheirkhabarov @HeirhabarovT, oscd.community Date: 2020-10-13 modified:2021-05-30 Tags:
-'attack.t1210'
-'attack.lateral-movement'
Logsource:
service: system
product: windows
Detection: selection: EventID: -'5805' -'5723'
keywords: - 'kali' - 'mimikatz' condition:selection and keywords Falsepositives: Level:critical