Exploitation of Remote Services T1210

Tactic: Lateral Movement

Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. A common goal for post-compromise exploitation of remote services is for lateral movement to enable access to a remote system.

Events covered

40 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 11FileCreate
SysmonEvent ID 19WmiEvent (WmiEventFilter activity detected)
SysmonEvent ID 20WmiEvent (WmiEventConsumer activity detected)
SysmonEvent ID 21WmiEvent (WmiEventConsumerToFilter activity detected)
SysmonEvent ID 22DNSEvent (DNS query)
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4625An account failed to log on.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4697A service was installed in the system.
Security-AuditingEvent ID 4698A scheduled task was created.
Security-AuditingEvent ID 4699A scheduled task was deleted.
Security-AuditingEvent ID 4700A scheduled task was enabled.
Security-AuditingEvent ID 4701A scheduled task was disabled.
Security-AuditingEvent ID 4702A scheduled task was updated.
Security-AuditingEvent ID 4724An attempt was made to reset an account's password.
Security-AuditingEvent ID 4742A computer account was changed.
Security-AuditingEvent ID 5145A network share object was checked to see whether client can be granted desired access.
Security-AuditingEvent ID 5152The Windows Filtering Platform blocked a packet.
Security-AuditingEvent ID 5154The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.
Security-AuditingEvent ID 5155The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.
Security-AuditingEvent ID 5156The Windows Filtering Platform has permitted a connection.
Security-AuditingEvent ID 5157The Windows Filtering Platform has blocked a connection.
Security-AuditingEvent ID 5158The Windows Filtering Platform has permitted a bind to a local port.
Security-AuditingEvent ID 5159The Windows Filtering Platform has blocked a bind to a local port.
Defender-DeviceEventsPowerShellCommandPowerShell command executed
Defender-DeviceLogonEventsLogonSuccessLogon succeeded
Defender-DeviceNetworkEventsNetworkSignatureInspectedNetwork signature inspected
Defender-DeviceProcessEventsanyProcess activity
Defender-DeviceTvmSoftwareVulnerabilitiesanySoftware vulnerabilities on devices
MSExchange-CmdletLogsEvent ID 6Event ID 6
MSExchange-CmdletLogsEvent ID 8Task <TaskName> throwing unhandled exception.
Audit-CVEEvent ID 1Possible detection of CVE: PossibleDetectionOfCVE.
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
NETLOGONEvent ID 5723Event ID 5723
NETLOGONEvent ID 5805Event ID 5805
Sysmon-for-LinuxEvent ID 1Process Create
TermDDEvent ID 50Event ID 50
TermDDEvent ID 56Event ID 56

Authoring guide

These 83 rules share fields, values, and exclusions.

Fields filtered most (102 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
event.type16eq 14, in 2start, creation, allowed, change, deletion
parent_process_name16eq 12, in 7, starts_with 3, wildcard 3, regex_match 2*.cgi, *.fcgi, apache2, (?i)(wmiprvse|mmc|explorer|services)\.exe, telnetd
EventType14eq 12, in 2exec, intrusionevent, microsoft.containerservice/managedclusters/diagnosticlogs/read, ProcessRollup2, exec_event
CommandLine13contains 9, regex_match 6, wildcard 6 /dev/shm/, /home/, /run/, * /dev/shm/*, * /run/*
process_name13eq 9, in 8, starts_with 2, ends_with 1, wildcard 1bash, busybox, csh, login, .
EventID9eq 9, in 24688, 4742, 1, 19, 20
process.args9in 6, wildcard 6, contains 3, eq 3, starts_with 3*../../../*, *.aws/credentials*, *.env*, -*f*, -c
Image8ends_with 4, starts_with 4, eq 3, wildcard 2, contains 1, is_null 1./, /bin/cat, /bin/chmod, :\windows\system32\csrss.exe, :\windows\system32\wininit.exe
ParentCommandLine8contains 6, wildcard 3, regex_match 1*--port*, */app/*.js*, */apps/*/*.js*, (?i)svchost\.exe\s-k\snetsvcs.+taskeng\.exe, \svchost.exe
host.os.type7eq 7
process.parent.interactive6eq 6false
ParentImage5contains 2, ends_with 2, wildcard 1/*/postfix*master, /bin/redis, \cmd.exe, \java.exe, \javaw.exe
sourcetype5eq 5cisco:sfw:estreamer, splunkd_access, splunkd_ui_access
Computer3eq 3adfs_servers, %domain_controllers%
DAVISRiskLevel3eq 2, ne 1CRITICAL

Top indicator values (748 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
131078
EventTypeeq
exec
7576
process.parent.interactiveeq
false
67
process_namein
bash
6202
process_namein
dash
6170
process_namein
sh
6197
process_namein
zsh
6196
process_namein
busybox
568
process_namein
csh
5159
process_namein
fish
5163
process_namein
ksh
5163
process_namein
tcsh
5156
process.argsin
-c
527
process.argsin
-cl
517
process.argsin
-lc
517
CommandLinecontains
ftp
46
CommandLinecontains
http
452
CommandLineregex_match
.*[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}(:[0-9]{1,5})?/.*
46
CommandLineregex_match
.*curl.* \-[a-zA-Z]*[oO]( .+|\-.*)?
46
CommandLineregex_match
.*wget.* \-[a-zA-Z]*O.*
46
CommandLinewildcard
* /dev/shm/*
45
CommandLinewildcard
* /run/*
45
CommandLinewildcard
* /tmp/*
45
CommandLinewildcard
* /var/run/*
45
CommandLinewildcard
* /var/tmp/*
45
CommandLinewildcard
* nc *
47
CommandLinewildcard
*#!*
45
CommandLinewildcard
*../../../*etc/*
45
CommandLinewildcard
*../../../*home/*/*
45
CommandLinewildcard
*../../../*root/*
45

Exclusions (446 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
parent_process_nameeq
apache2
3
parent_process_nameeq
ruby
3
parent_process_nameeq
asterisk
2
parent_process_nameeq
httpd
2
parent_process_nameeq
java
2
parent_process_nameeq
node
2
Accountends_with
$
2
CommandLinein
runc init
2
Imagewildcard
/tmp/newroot/*
2
azure.platformlogs.properties.log.user.usernameeq
aksservice
2
azure.platformlogs.properties.log.user.usernameeq
hcpservice
2
azure.platformlogs.properties.log.user.usernameeq
readinesschecker
2
azure.platformlogs.properties.log.user.usernamestarts_with
system:node:
2
parent_process_namein
apache2
2
parent_process_namein
httpd
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 16 rules

Elastic 29 rules

Splunk 15 rules

Kusto 21 rules

YARA-L 1 rule

Panther 1 rule