diff --git a/rules/windows/powershell/powershell_prompt_credentials.yml b/rules/windows/powershell/powershell_prompt_credentials.yml new file mode 100644 index 000000000..2e7a67629 --- /dev/null +++ b/rules/windows/powershell/powershell_prompt_credentials.yml @@ -0,0 +1,19 @@ +title: PowerShell Credential Prompt +status: experimental +description: Detects PowerShell calling a credential prompt +reference: + - https://twitter.com/JohnLaTwC/status/850381440629981184 + - https://t.co/ezOTGy1a1G +author: John Lambert (idea), Florian Roth (rule) +logsource: + product: windows + service: powershell + description: 'Script block logging must be enabled' +detection: + selection: + EventID: 4104 + keyword: 'PromptForCredential' + condition: selection and keyword +falsepositives: + - Unknown +level: high