Merge pull request #9 from iliaselmatani/patch-1

Create win_pass_the_hash.yml
This commit is contained in:
Florian Roth
2017-03-13 16:16:55 +01:00
committed by GitHub
@@ -0,0 +1,28 @@
title: Detects Pass the Hash Activity
status: experimental
description: 'Detects the attack technique pass the hash which is used to move laterally inside the network'
reference: https://github.com/iadgov/Event-Forwarding-Guidance/tree/master/Events
author: Ilias el Matani (rule), The Information Assurance Directorate at the NSA (method)
logsource:
product: windows
service: security
description: The successful use of PtH for lateral movement between workstations would trigger event ID 4624, a failed logon attempt would trigger an event ID 4625
detection:
selection:
- EventID: 4624
LogonType: '3'
LogonProcess: 'NtLmSsp'
KeyLength: '0'
WorkstationName: %Workstations%
ComputerName: %Workstations%
- EventID: 4625
LogonType: '3'
LogonProcess: 'NtLmSsp'
KeyLength: '0'
WorkstationName: %Workstations%
ComputerName: %Workstations%
condition: selection
falsepositives:
- Administrator activity
- Penetration tests
level: medium