Files
sigma-rules/rules/windows
Samirbous 03836d45fa [New Rule] Potential Local NTLM Relay via HTTP (#1947)
* [New Rule] Potential Local NTLM Relay via HTTP

Detect attempt to elevate privileges via coercing a privileged service to connect to a local rogue HTTP endpoint, leading to NTLM relay, example of logs while testing https://github.com/med0x2e/NTLMRelay2Self (step 5):

* Update credential_access_relay_ntlm_auth_via_http_spoolss.toml

* Update credential_access_relay_ntlm_auth_via_http_spoolss.toml

Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
2022-05-06 21:07:27 +02:00
..