Merge pull request #9 from iliaselmatani/patch-1
Create win_pass_the_hash.yml
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
title: Detects Pass the Hash Activity
|
||||
status: experimental
|
||||
description: 'Detects the attack technique pass the hash which is used to move laterally inside the network'
|
||||
reference: https://github.com/iadgov/Event-Forwarding-Guidance/tree/master/Events
|
||||
author: Ilias el Matani (rule), The Information Assurance Directorate at the NSA (method)
|
||||
logsource:
|
||||
product: windows
|
||||
service: security
|
||||
description: The successful use of PtH for lateral movement between workstations would trigger event ID 4624, a failed logon attempt would trigger an event ID 4625
|
||||
detection:
|
||||
selection:
|
||||
- EventID: 4624
|
||||
LogonType: '3'
|
||||
LogonProcess: 'NtLmSsp'
|
||||
KeyLength: '0'
|
||||
WorkstationName: %Workstations%
|
||||
ComputerName: %Workstations%
|
||||
- EventID: 4625
|
||||
LogonType: '3'
|
||||
LogonProcess: 'NtLmSsp'
|
||||
KeyLength: '0'
|
||||
WorkstationName: %Workstations%
|
||||
ComputerName: %Workstations%
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Administrator activity
|
||||
- Penetration tests
|
||||
level: medium
|
||||
Reference in New Issue
Block a user