c1a0398c3f
Updates MITRE Technique IDs for Credential Access DRs
(cherry picked from commit f6421d8c53)
58 lines
1.9 KiB
TOML
58 lines
1.9 KiB
TOML
[metadata]
|
|
creation_date = "2020/08/13"
|
|
maturity = "production"
|
|
updated_date = "2021/05/10"
|
|
|
|
[rule]
|
|
author = ["Elastic"]
|
|
description = """
|
|
Identifies the creation or modification of Domain Backup private keys. Adversaries may extract the Data Protection API
|
|
(DPAPI) domain backup key from a Domain Controller (DC) to be able to decrypt any domain user master key file.
|
|
"""
|
|
from = "now-9m"
|
|
index = ["winlogbeat-*", "logs-endpoint.events.*", "logs-windows.*"]
|
|
language = "eql"
|
|
license = "Elastic License v2"
|
|
name = "Creation or Modification of Domain Backup DPAPI private key"
|
|
note = """## Triage and analysis
|
|
|
|
Domain DPAPI Backup keys are stored on domain controllers and can be dumped remotely with tools such as Mimikatz. The resulting .pvk private key can be used to decrypt ANY domain user masterkeys, which then can be used to decrypt any secrets protected by those keys."""
|
|
references = [
|
|
"https://www.dsinternals.com/en/retrieving-dpapi-backup-keys-from-active-directory/",
|
|
"https://www.harmj0y.net/blog/redteaming/operational-guidance-for-offensive-user-dpapi-abuse/",
|
|
]
|
|
risk_score = 73
|
|
rule_id = "b83a7e96-2eb3-4edf-8346-427b6858d3bd"
|
|
severity = "high"
|
|
tags = ["Elastic", "Host", "Windows", "Threat Detection", "Credential Access"]
|
|
timestamp_override = "event.ingested"
|
|
type = "eql"
|
|
|
|
query = '''
|
|
file where event.type != "deletion" and file.name : ("ntds_capi_*.pfx", "ntds_capi_*.pvk")
|
|
'''
|
|
|
|
|
|
[[rule.threat]]
|
|
framework = "MITRE ATT&CK"
|
|
[[rule.threat.technique]]
|
|
id = "T1552"
|
|
reference = "https://attack.mitre.org/techniques/T1552/"
|
|
name = "Unsecured Credentials"
|
|
[[rule.threat.technique.subtechnique]]
|
|
id = "T1552.004"
|
|
reference = "https://attack.mitre.org/techniques/T1552/004/"
|
|
name = "Private Keys"
|
|
[[rule.threat.technique]]
|
|
id = "T1555"
|
|
name = "Credentials from Password Stores"
|
|
reference = "https://attack.mitre.org/techniques/T1555/"
|
|
|
|
|
|
|
|
[rule.threat.tactic]
|
|
id = "TA0006"
|
|
reference = "https://attack.mitre.org/tactics/TA0006/"
|
|
name = "Credential Access"
|
|
|