Samirbous
ad2c069baa
[New Rule] Potential Remote Credential Access via Registry ( #1804 )
...
* [New Rule] Potential Remote Credential Access via Registry
4624 logon followed by hive file creation by regsvc svchost.exe by same user.name and host.id. This matches on secretdsdump and other similar implementations. require to correlation Elastic endpoint file events with System integration logs (4624).
Example of data :
* Delete workspace.xml
* Update credential_access_remote_sam_secretsdump.toml
* Update credential_access_remote_sam_secretsdump.toml
* add non ecs field
* Update non-ecs-schema.json
* Update credential_access_remote_sam_secretsdump.toml
* Update rules/windows/credential_access_remote_sam_secretsdump.toml
Co-authored-by: Jonhnathan <jonhnathancesar@gmail.com >
* Update rules/windows/credential_access_remote_sam_secretsdump.toml
Co-authored-by: Jonhnathan <jonhnathancesar@gmail.com >
* Update rules/windows/credential_access_remote_sam_secretsdump.toml
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com >
Co-authored-by: Jonhnathan <jonhnathancesar@gmail.com >
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com >
(cherry picked from commit a6582351b5 )
2022-03-03 15:31:20 +00:00
..
2021-10-26 12:16:31 -03:00
2022-03-03 10:39:59 +00:00
2022-03-03 10:39:59 +00:00
2022-03-03 10:39:59 +00:00
2021-09-23 12:08:38 -05:00
2021-06-15 09:22:59 -04:00
2022-02-16 02:07:27 +00:00
2021-09-23 12:08:38 -05:00
2021-03-03 22:12:11 -09:00
2022-02-16 02:00:28 +00:00
2022-02-15 12:59:15 +00:00
2021-09-23 12:08:38 -05:00
2021-04-30 11:21:12 -08:00
2021-05-10 13:40:56 -08:00
2021-10-26 12:16:31 -03:00
2021-10-13 21:46:36 -03:00
2021-09-23 12:08:38 -05:00
2021-09-23 12:08:38 -05:00
2021-10-19 20:52:53 -08:00
2021-09-21 11:04:16 -05:00
2021-04-30 11:21:12 -08:00
2022-03-02 00:41:56 +00:00
2022-01-31 15:34:02 +00:00
2021-09-21 11:04:16 -05:00
2021-09-21 11:04:16 -05:00
2021-03-03 22:12:11 -09:00
2021-03-03 22:12:11 -09:00
2022-02-16 16:44:51 +00:00
2021-09-21 11:04:16 -05:00
2022-02-24 13:16:42 +00:00
2021-04-30 11:21:12 -08:00
2022-01-28 19:43:39 +00:00
2022-02-04 18:40:39 +00:00
2022-03-02 09:14:52 +00:00
2022-03-02 00:41:56 +00:00
2022-03-02 00:41:56 +00:00
2022-03-02 00:41:56 +00:00
2021-12-07 15:42:58 -09:00
2022-03-03 15:31:20 +00:00
2021-09-21 11:04:16 -05:00
2022-01-31 15:25:23 +00:00
2022-02-04 18:51:25 +00:00
2022-02-16 16:44:51 +00:00
2022-02-16 16:44:51 +00:00
2022-03-02 00:41:56 +00:00
2022-02-16 16:44:51 +00:00
2021-12-08 11:16:14 +01:00
2021-04-30 11:21:12 -08:00
2022-03-02 00:41:56 +00:00
2021-11-25 13:25:21 -03:00
2021-10-26 12:16:31 -03:00
2021-09-24 12:04:56 -05:00
2021-04-30 11:21:12 -08:00
2021-03-03 22:12:11 -09:00
2021-03-03 22:12:11 -09:00
2022-02-15 12:59:15 +00:00
2022-03-02 00:41:56 +00:00
2021-04-30 11:21:12 -08:00
2022-02-04 18:46:55 +00:00
2021-09-23 12:08:38 -05:00
2021-10-26 12:16:31 -03:00
2021-09-23 12:08:38 -05:00
2021-12-07 15:42:58 -09:00
2021-09-23 12:08:38 -05:00
2021-09-23 12:08:38 -05:00
2021-09-23 12:08:38 -05:00
2021-12-07 15:42:58 -09:00
2021-03-03 22:12:11 -09:00
2021-09-23 12:08:38 -05:00
2021-10-26 12:16:31 -03:00
2021-09-23 12:08:38 -05:00
2021-09-23 12:08:38 -05:00
2021-04-30 11:21:12 -08:00
2021-04-30 11:21:12 -08:00
2021-10-05 16:38:01 -03:00
2021-10-19 20:52:53 -08:00
2022-02-15 12:59:15 +00:00
2021-09-23 12:08:38 -05:00
2021-03-03 22:12:11 -09:00
2021-10-13 21:46:36 -03:00
2021-03-03 22:12:11 -09:00
2021-09-23 12:08:38 -05:00
2021-04-30 11:21:12 -08:00
2022-01-28 19:43:39 +00:00
2021-10-13 21:46:36 -03:00
2022-03-02 00:41:56 +00:00
2021-11-14 17:01:13 -09:00
2022-03-02 00:41:56 +00:00
2021-09-23 12:08:38 -05:00
2021-09-23 12:08:38 -05:00
2021-08-03 13:07:47 -08:00
2021-10-13 21:46:36 -03:00
2021-06-15 09:22:59 -04:00
2021-03-03 22:12:11 -09:00
2021-07-15 22:55:46 +02:00
2022-02-16 16:44:51 +00:00
2022-03-03 10:39:59 +00:00
2022-03-02 00:41:56 +00:00
2021-03-03 22:12:11 -09:00
2022-03-02 00:41:56 +00:00
2021-09-23 12:08:38 -05:00
2021-07-22 09:08:58 -08:00
2022-02-15 12:59:15 +00:00
2021-05-10 13:40:56 -08:00
2022-02-15 12:59:15 +00:00
2022-02-15 12:59:15 +00:00
2021-11-17 11:41:07 -09:00
2021-05-28 14:44:07 -04:00
2021-04-30 11:21:12 -08:00
2021-12-07 15:42:58 -09:00
2021-11-30 21:35:43 +01:00
2021-04-14 23:54:39 +02:00
2022-01-28 19:43:39 +00:00
2021-10-26 12:16:31 -03:00
2021-04-30 11:21:12 -08:00
2021-03-03 22:12:11 -09:00
2021-09-23 12:08:38 -05:00
2021-05-28 15:09:09 -04:00
2021-06-15 09:22:59 -04:00
2021-03-08 14:12:29 -09:00
2021-04-30 11:21:12 -08:00
2021-09-23 12:08:38 -05:00
2021-12-07 15:52:38 -09:00
2022-03-03 14:24:27 +00:00
2022-03-02 00:41:56 +00:00
2021-09-23 12:08:38 -05:00
2021-03-03 22:12:11 -09:00
2022-03-02 00:41:56 +00:00
2021-08-14 20:29:10 -08:00
2021-03-03 22:12:11 -09:00
2022-03-02 00:41:56 +00:00
2022-02-16 02:07:27 +00:00
2022-02-16 16:44:51 +00:00
2021-03-03 22:12:11 -09:00
2021-09-23 12:08:38 -05:00
2021-04-30 11:21:12 -08:00
2021-03-03 22:12:11 -09:00
2021-03-03 22:12:11 -09:00
2021-03-03 22:12:11 -09:00
2021-06-15 09:22:59 -04:00
2021-04-30 11:21:12 -08:00
2021-04-30 11:21:12 -08:00
2021-03-18 15:14:22 +01:00
2021-09-23 12:08:38 -05:00
2021-03-03 22:12:11 -09:00
2021-09-23 12:08:38 -05:00
2021-03-03 22:12:11 -09:00
2021-05-10 13:40:56 -08:00
2021-09-23 12:08:38 -05:00
2021-07-29 10:56:13 -08:00
2021-07-22 09:08:58 -08:00
2022-03-02 00:41:56 +00:00
2022-03-03 10:39:59 +00:00
2021-03-03 22:12:11 -09:00
2022-02-16 00:25:10 +00:00
2021-10-26 12:16:31 -03:00
2021-05-10 13:40:56 -08:00
2021-03-08 14:12:29 -09:00
2021-08-03 13:07:47 -08:00
2021-04-30 11:21:12 -08:00
2021-10-19 20:52:53 -08:00
2021-03-03 22:12:11 -09:00
2021-03-03 22:12:11 -09:00
2021-10-26 12:16:31 -03:00
2021-04-30 11:21:12 -08:00
2021-04-30 11:21:12 -08:00
2021-12-07 15:42:58 -09:00
2021-09-23 12:08:38 -05:00
2021-09-23 12:08:38 -05:00
2021-09-23 12:08:38 -05:00
2022-02-11 17:18:12 +00:00
2021-10-26 12:16:31 -03:00
2021-09-23 12:08:38 -05:00
2021-04-30 11:21:12 -08:00
2021-03-08 14:12:29 -09:00
2021-05-10 13:40:56 -08:00
2021-03-08 14:12:29 -09:00
2021-10-26 12:16:31 -03:00
2021-09-08 13:30:46 -05:00
2021-04-30 11:21:12 -08:00
2021-05-10 13:40:56 -08:00
2021-05-10 13:40:56 -08:00
2021-04-14 00:10:29 +02:00
2021-03-03 22:12:11 -09:00
2022-03-02 00:41:56 +00:00
2022-01-13 16:40:10 -03:00
2022-01-13 16:40:10 -03:00
2022-02-15 12:59:15 +00:00
2021-09-23 12:08:38 -05:00
2022-03-02 00:41:56 +00:00
2021-04-14 22:09:49 +02:00
2022-01-13 16:40:10 -03:00
2021-03-03 22:12:11 -09:00
2021-03-03 22:12:11 -09:00
2022-01-13 16:40:10 -03:00
2022-01-13 16:40:10 -03:00
2021-03-03 22:12:11 -09:00
2022-03-02 00:41:56 +00:00
2022-02-15 12:59:15 +00:00
2022-02-15 12:59:15 +00:00
2021-03-03 22:12:11 -09:00
2022-01-13 16:40:10 -03:00
2022-01-28 19:43:39 +00:00
2022-02-16 02:07:27 +00:00
2021-03-03 22:12:11 -09:00
2021-03-03 22:12:11 -09:00
2022-02-01 13:17:28 +00:00
2021-04-30 11:21:12 -08:00
2021-03-03 22:12:11 -09:00
2022-02-15 12:59:15 +00:00
2021-03-03 22:12:11 -09:00
2021-09-23 12:08:38 -05:00
2022-02-15 12:59:15 +00:00
2022-03-02 00:41:56 +00:00
2021-09-23 12:08:38 -05:00
2021-09-23 12:08:38 -05:00
2022-03-02 00:41:56 +00:00
2021-10-26 12:16:31 -03:00
2021-03-03 22:12:11 -09:00
2021-03-03 22:12:11 -09:00
2022-02-01 13:11:57 +00:00
2021-10-26 12:16:31 -03:00
2021-03-03 22:12:11 -09:00
2022-03-02 00:41:56 +00:00
2022-01-27 12:27:38 +00:00
2022-02-15 12:59:15 +00:00
2021-03-03 22:12:11 -09:00
2022-02-15 12:59:15 +00:00
2021-03-03 22:12:11 -09:00
2021-03-03 22:12:11 -09:00
2021-03-03 22:12:11 -09:00
2022-02-15 12:59:15 +00:00
2021-03-08 14:12:29 -09:00
2021-09-23 12:08:38 -05:00
2022-02-15 12:59:15 +00:00
2021-10-26 12:16:31 -03:00
2022-03-02 00:41:56 +00:00
2021-09-23 12:08:38 -05:00
2022-01-28 19:43:39 +00:00
2021-09-23 12:08:38 -05:00
2021-04-30 11:21:12 -08:00
2021-04-13 23:25:30 +02:00
2022-02-15 12:59:15 +00:00
2022-02-15 12:59:15 +00:00
2021-09-23 12:08:38 -05:00
2021-03-03 22:12:11 -09:00
2021-09-23 12:08:38 -05:00
2022-02-15 12:59:15 +00:00
2021-10-26 12:16:31 -03:00
2022-02-15 12:59:15 +00:00
2022-03-02 00:41:56 +00:00
2022-03-02 00:41:56 +00:00
2022-03-02 00:41:56 +00:00
2022-03-02 00:41:56 +00:00
2022-02-16 02:07:27 +00:00
2021-03-03 22:12:11 -09:00
2021-06-01 09:29:09 -04:00
2022-02-15 12:59:15 +00:00
2021-07-07 18:56:39 +02:00
2022-02-15 12:59:15 +00:00
2022-02-15 12:59:15 +00:00
2021-04-30 11:21:12 -08:00
2021-07-07 18:56:39 +02:00
2021-05-10 13:40:56 -08:00
2022-02-15 12:59:15 +00:00
2022-01-27 14:49:15 +00:00
2021-08-04 14:16:10 -08:00
2021-08-04 14:16:10 -08:00
2021-08-04 14:16:10 -08:00
2021-08-04 14:16:10 -08:00
2021-08-04 14:16:10 -08:00
2021-08-04 14:16:10 -08:00
2021-08-04 14:16:10 -08:00
2021-08-04 14:16:10 -08:00
2021-08-04 14:16:10 -08:00
2021-09-30 12:54:15 -08:00
2022-02-16 00:25:10 +00:00
2021-03-08 14:12:29 -09:00
2021-12-08 11:21:04 +01:00
2022-02-11 20:59:20 +00:00
2021-10-13 21:46:36 -03:00