Use Alternate Authentication Material T1550

Tactic: Lateral Movement

Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal system access controls.

Events covered

23 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 10ProcessAccess
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4625An account failed to log on.
Security-AuditingEvent ID 4648A logon was attempted using explicit credentials.
Security-AuditingEvent ID 4657A registry value was modified.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4768A Kerberos authentication ticket (TGT) was requested.
Security-AuditingEvent ID 4769A Kerberos service ticket was requested.
Security-AuditingEvent ID 4776The domain controller attempted to validate the credentials for an account.
Security-AuditingEvent ID 4887Certificate Services approved a certificate request and issued a certificate.
Security-AuditingEvent ID 5136A directory service object was modified.
Security-AuditingEvent ID 5145A network share object was checked to see whether client can be granted desired access.
ESFexecProcess Execution
LsaSrvEvent ID 6038Microsoft Windows Server has detected that NTLM authentication is presently being used between clients and this server.
LsaSrvEvent ID 6039Microsoft Windows Server has detected that NTLM authentication is being used between clients and this server.
AppLockerEvent ID 8002FilePathBuffer was allowed to run.
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).

Authoring guide

These 133 rules share fields, values, and exclusions.

Fields filtered most (236 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
data_stream.dataset35eq 32, in 3azure.signinlogs, aws.cloudtrail, azure.auditlogs, azure.graphactivitylogs, okta.system
EventType24eq 19, in 5, is_not_null 1assumerole, sign-in activity, assumerolewithwebidentity, exec, getfederationtoken
event.outcome21eq 21success
EventID16eq 15, in 24768, 4624, 4688, 4769, 1
event.category11eq 11authentication, configuration, process, network
Provider_Name10eq 10sts.amazonaws.com, signin.amazonaws.com, lsasrv
host.os.type10eq 9, in 1
aws::eventName9eq 8, in 1UpdateLoginProfile, CreateAccessKey, CreateLoginProfile, DeleteLoginProfile, GetSessionToken
aws::eventSource9eq 9iam.amazonaws.com, sts.amazonaws.com, signin.amazonaws.com, bedrock.amazonaws.com
azure_ad::app_id9eq 6, in 2, is_not_null 129d9ed98-a469-4536-ade2-f981bc1d605e, 00b41c95-dab0-4487-9791-b9d2c32c80f2, 04b07795-8ddb-461a-bbee-02f9e1bf7b46, 0ec893e0-5785-4de6-99da-4ed124e5296c
azure_ad::user_type9eq 8, is_not_null 1member, Member
event.dataset9eq 9aws.cloudtrail, github.audit, o365.audit
event.type9eq 7, in 1, ne 1start, change, access, deletion, process_started
aws::userIdentity.type8eq 8assumedrole, iamuser, AssumedRole, IAMUser, awsservice
CommandLine7contains 6, eq 1, in 1, regex_match 1 -cn , -computername , -cp , -p , -u

Top indicator values (757 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
21369
data_stream.dataseteq
azure.signinlogs
1536
data_stream.dataseteq
aws.cloudtrail
6169
Provider_Nameeq
sts.amazonaws.com
711
keyeq
user-agent
712
azure_ad::app_ideq
29d9ed98-a469-4536-ade2-f981bc1d605e
68
azure_ad::user_typeeq
member
611
LogonTypeeq
NewCredentials
58
LogonTypeeq
Network
341
event.categoryeq
authentication
534
DestinationPorteq
88
47
EventTypeeq
sign-in activity
47
EventTypeeq
assumerole
33
LogonProcessNameeq
seclogo
45
OperationNamecontains
certificates and secrets management
46
OperationNamecontains
add service principal
34
Resulteq
success
431
aws::eventSourceeq
iam.amazonaws.com
428
aws::eventSourceeq
sts.amazonaws.com
36
displayNamecontains
@
45
displayNameeq
keydescription
45
event.dataseteq
aws.cloudtrail
417
event.typeeq
start
41078
typeeq
application
44
userPrincipalNamecontains
@
45
Categoryeq
applicationmanagement
313
OperationNameeq
consent to application
35
aws::userIdentity.typeeq
assumedrole
39
azure.signinlogs.properties.token_protection_status_details.sign_in_session_statuseq
unbound
34
azure_ad::authentication_protocoleq
devicecode
33

Exclusions (338 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imagewildcard
?:\windows\system32\lsass.exe
2
azure_ad::app_idin
29d9ed98-a469-4536-ade2-f981bc1d605e
2
azure_ad::app_idin
4813382a-8fa7-425e-ab75-3b753aab3abb
2
azure_ad::app_idin
95de633a-083e-42f5-b444-a4295d8e9314
2
azure_ad::app_idin
9ba1a5c7-f17a-4de9-a1f1-6178c8d51223
2
azure_ad::app_idin
ab9b8c07-8f02-4f72-87fa-80105867a763
2
azure_ad::app_idin
fc0f3af4-6835-4174-b806-f7db311fd2f3
2
resultSignaturene
SUCCESS
2
source.as.organization.nameeq
microsoft-corp-msn-as-block
2
AlertNamecontains
0299
1
AppIdin
cb1056e2-e479-49de-ae31-7812af012ed8
1
AppIdin
cf6d7e68-f018-4e0a-a7b3-126e053fb88d
1
Esql.azure_signinlogs_properties_app_id_coalescein
00000007-0000-0000-c000-000000000000
1
Esql.azure_signinlogs_properties_app_id_coalescein
01fc33a7-78ba-4d2f-a4b7-768e336e890e
1
Esql.azure_signinlogs_properties_app_id_coalescein
0ec893e0-5785-4de6-99da-4ed124e5296c
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 18 rules

Elastic 61 rules

Splunk 14 rules

Kusto 14 rules

YARA-L 5 rules

Panther 21 rules