Forced Authentication T1187

Tactic: Credential Access

Adversaries may gather credential material by invoking or forcing a user to automatically provide authentication information through a mechanism in which they can intercept.

Events covered

16 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 30 rules share fields, values, and exclusions.

Fields filtered most (54 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventID9eq 8, in 35145, 4624, 4625, 5137, 4662
host.os.type7eq 7
CommandLine6contains 4, match 1, regex_match 1, wildcard 1(?i)\s(-u|--user)\s*:, *ms-screensketch*edit*&filePath=%5C%5C*, *ms-screensketch*edit*&filePath=*\\*, *ms-screensketch*edit*&filePath=http*, --ntlm
src_ip6is_not_null 4, ne 4, eq 1, in 1::1, 127.0.0.1, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16
LogonType4eq 4Network
user4ends_with 4, ne 1$
AuthenticationPackageName3eq 3NTLM, kerberos, ntlm
Channel3eq 3, in 3
DestinationPort3in 2, eq 1445, 139, 80, 9389
Image3ends_with 3\7z.exe, \curl.exe, \explorer.exe, \snippingtool.exe, \winrar.exe
QueryName3contains 2, wildcard 1*uwhrc*baaaa*, 1uwhrc, aaaaa, baaaa, uwhrca
eventtype3eq 3
file.name3eq 3efsrpc, dhcpserver, dnsserver, fssagentrpc, lsarpc
process_name3eq 3rundll32.exe, snippingtool.exe
AdditionalInfo2contains 1, wildcard 1*UWhRC*BAAAA*MicrosoftDNS*, 1uwhrca, aaaaa, ybaaaa

Top indicator values (137 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventIDeq
5145
523
EventIDeq
5137
314
EventIDeq
4662
215
EventIDeq
5136
245
LogonTypeeq
Network
441
src_ipne
127.0.0.1
423
src_ipne
::1
421
userends_with
$
45
EventIDin
4624
37
EventIDin
4625
37
file.nameeq
efsrpc
33
file.nameeq
fssagentrpc
33
file.nameeq
lsarpc
33
file.nameeq
lsass
33
file.nameeq
netdfs
33
file.nameeq
netlogon
33
file.nameeq
samr
33
file.nameeq
spoolss
33
file.nameeq
dhcpserver
22
file.nameeq
dnsserver
22
file.nameeq
eventlog
22
file.nameeq
srvsvc
22
file.nameeq
winreg
22
file.nameeq
winspipe
22
DestinationPortin
445
210
ObjectClasseq
dnsnode
23
RelativeTargetNameeq
lsarpc
23
SubjectUserNameeq
anonymous logon
23
computer_namestarts_with
substring(user.name, 0, (-1))
22
event.typeeq
start
21078

Exclusions (39 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
src_ipends_with
host.ip
4
computer_namestarts_with
substring(user.name, 0, (-1))
2
Esql.server_webdav_serverin
github.com
1
Esql.server_webdav_serverin
google.com
1
Esql.server_webdav_serverin
live.net
1
Esql.server_webdav_serverin
sharepoint.com
1
Esql.server_webdav_serverin
www.elastic.co
1
Esql.server_webdav_serverin
www.google.com
1
Esql.server_webdav_serverregex_match
(10\.(\d{1,3}\.){2}\d{1,3}|172\.(1[6-9]|2\d|3[0-1])\.(\d{1,3}\.)\d{1,3}|192\....
1
ParentImagewildcard
?:\program files\windowsapps\microsoft.screensketch_*\snippingtool\snippingtool.exe
1
ParentImagewildcard
?:\windows\system32\svchost.exe
1
dest_ipin
10.0.0.0/8
1
dest_ipin
100.64.0.0/10
1
dest_ipin
127.0.0.0/8
1
dest_ipin
169.254.0.0/16
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 9 rules

Elastic 11 rules

Splunk 6 rules

Kusto 4 rules