Detection rules › By event
Microsoft-Windows-Security-Auditing Event ID 5145
Sigma (43)
- Active Directory honeypot used for lateral movement
- Azure Active Directory Connect credentials dump via network share
- BlueSky Ransomware Artefacts
- CrackMaxpExec share permission enumeration
- Credentials (protected by DPAPI) dump via network share
- CVE-2021-1675 Print Spooler Exploitation IPC Access
- DCERPC SMB Spoolss Named Pipe
- DCOM InternetExplorer.Application Iertutil DLL Hijack - Security
- Discovery for print spooler bug abuse (NTLM hash retrivial) via named pipe
- DNS hosts file accessed via network share
- First Time Seen Remote Named Pipe
- Impacket PsExec Execution
- Impacket WMIexec execution via SMB admin share
- LSASS credential dump with LSASSY (admin share)
- Massive remote schedule task creation via named pipes (CrackMapExec with ATexec)
- Massive remote service creation via named pipes (TChopper, CME)
- Massive remote service creation via named pipes - Tchopper
- NetSYnc attack
- Persistence and Execution at Scale via GPO Scheduled Task
- Possible Impacket SecretDump Remote Activity
- Possible PetitPotam Coerce Authentication Attempt
- Protected Storage Service Access
- PSexec execution over SMB share
- Remote schedule task creation via named pipes (ATexec)
- Remote Service Activity via SVCCTL Named Pipe
- Remote service creation via named pipes
- Remote shell execution via SMB admin share
- Remote Task Creation via ATSVC Named Pipe
- Secretdump password dumping via SMB admin share
- Shared folder access with forged Golden ticket
- SharpHound enumeration via SMB named pipes
- SMB admin share accessed
- SMB Create Remote File Admin Share
- Startup/Logon Script Added to Group Policy Object
- Suspicious Access to Sensitive File Extensions
- Suspicious PsExec Execution
- T1047 Wmiprvse Wbemcomn DLL Hijack
- Transferring Files with Credential Data via Network Shares
- User application credentials dump via network share (DonPapi, Lazagne)
- User browser credentials dump via network share (DonPapi, Lazagne)
- User files dump via network share (DonPapi, Lazagne)
- User password change without previous password known - SetNTLM (Mimikatz)
- Windows Network Access Suspicious desktop.ini Action
Elastic (8)
- Active Directory Forced Authentication from Linux Host - SMB Named Pipes
- Potential Kerberos Relay Attack against a Computer Account
- Potential Machine Account Relay Attack via SMB
- Potential Network Share Discovery
- Potential NTLM Relay Attack against a Computer Account
- Scheduled Task Execution at Scale via GPO
- Startup/Logon Script added to Group Policy Object
- Suspicious Remote Registry Access via SeBackupPrivilege
Splunk (16)
- Certificate Enumeration - Windows (Windows Event Log)
- Command Output Redirected to Localhost (Windows Event Log)
- Executable File Written in Administrative SMB Share
- High Frequency Copy Of Files In Network Share
- Impacket PSexec (Windows Event Log)
- PetitPotam Network Share Access Request
- Potential SMB Activity from External IP - Windows (Windows Event Log)
- SecretsDump Credential Harvest (Windows Event Log)
- SMB Write Access on Administrative Share (Windows Event Log)
- Suspicious Spool Authentication (Windows Event Log)
- Windows Admin$ Share Access (Windows Event Log)
- Windows Administrative Shares Accessed On Multiple Hosts
- Windows C$ Share Access (Windows Event Log)
- Windows IPC$ Share Access (Windows Event Log)
- Windows Scheduled Task Created in a Group Policy Object
- Windows Share Multiple File Access (Windows Event Log)