Exploitation for Credential Access T1212

Tactic: Credential Access

Adversaries may exploit software vulnerabilities in an attempt to collect credentials. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code.

Events covered

10 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 23 rules share fields, values, and exclusions.

Fields filtered most (45 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
process_name5eq 4, in 1cat, dd, egrep, fgrep, kernel
host.os.type4eq 4
EventType3in 2, eq 1exec, exec_event, ProcessRollup2, start
event.type3eq 3start
process.args3wildcard 2, eq 1, in 1, starts_with 1-eo, /tmp/, ?:\windows\system32\davclnt.dll,davsetcookie, ?:\windows\syswow64\davclnt.dll,davsetcookie, command
ActionUncommonlyPerformedByUser2eq 2True
Authorization2contains 2virtualmachines
CommandLine2contains 1, wildcard 1/print/pipe/, /proc/*/mem, c:\windows\system32\davclnt.dll,davsetcookie, http
StartTime2ge 2, le 2UEBAWindowEnd, UEBAWindowStart
UEBASourceIPLocation2is_not_null 2
aws::eventSource2eq 2Azure AD
azure_ad::operation_name_value2eq 2microsoft.compute/virtualmachines/runcommand/action
list_ActivityStatusValue2contains 2succeeded, success
sourcetype2eq 2kube:container:controller
user2is_not_null 2

Top indicator values (210 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
31078
ActionUncommonlyPerformedByUsereq
True
22
Authorizationcontains
virtualmachines
23
EventTypein
exec
2201
EventTypein
exec_event
2149
EventTypein
start
2163
StartTimege
UEBAWindowStart
22
StartTimele
UEBAWindowEnd
22
aws::eventSourceeq
Azure AD
22
azure_ad::operation_name_valueeq
microsoft.compute/virtualmachines/runcommand/action
24
list_ActivityStatusValuecontains
succeeded
23
list_ActivityStatusValuecontains
success
23
sourcetypeeq
kube:container:controller
22
AIPCallcontains
name
12
Actioneq
vulnerabilityAlert
1
ActionTypestarts_with
AppControl
15
ActivityTypecontains
unauthorizedaccess:iamuser/consoleloginsuccess.b
12
ActivityTypecontains
unauthorizedaccess:iamuser/instancecredentialexfiltration.insideaws
12
ActivityTypecontains
unauthorizedaccess:iamuser/instancecredentialexfiltration.outsideaws
12
ActivityTypecontains
unauthorizedaccess:iamuser/maliciousipcaller
1
ActivityTypecontains
unauthorizedaccess:iamuser/maliciousipcaller.custom
12
ActivityTypecontains
unauthorizedaccess:iamuser/toripcaller
12
AppDisplayNameeq
Azure Portal
12
CommandLinecontains
/print/pipe/
1
CommandLinecontains
c:\windows\system32\davclnt.dll,davsetcookie
13
CommandLinecontains
http
152
CommandLinecontains
spoolss
1
CommandLinecontains
srvsvc
1
CommandLinewildcard
/proc/*/mem
1
ControlName_seq
AzureSecureScoreBlockLegacyAuthentication
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 5 rules

Elastic 6 rules

Splunk 3 rules

Kusto 9 rules