Detection rules › Sigma
Uncommon Connection to Active Directory Web Services
Detects uncommon network connections to the Active Directory Web Services (ADWS) from processes not typically associated with ADWS management.
Known false positives
- ADWS is used by a number of legitimate applications that need to interact with Active Directory. These applications should be added to the allow-listing to avoid false positives.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Discovery |
Telemetry coverage
| Provider | Record / event type |
|---|---|
| Sysmon | Event ID 3: Network connection |
Rule body
title: Uncommon Connection to Active Directory Web Services
id: b3ad3c0f-c949-47a1-a30e-b0491ccae876
status: test
description: |
Detects uncommon network connections to the Active Directory Web Services (ADWS) from processes not typically associated with ADWS management.
references:
- https://medium.com/falconforce/soaphound-tool-to-collect-active-directory-data-via-adws-165aca78288c
- https://github.com/FalconForceTeam/FalconFriday/blob/a9219dfcfd89836f34660223f47d766982bdce46/Discovery/ADWS_Connection_from_Unexpected_Binary-Win.md
author: '@kostastsale'
date: 2024-01-26
tags:
- attack.discovery
- attack.t1087
logsource:
category: network_connection
product: windows
detection:
selection:
Initiated: true
DestinationPort: 9389
filter_main_dsac:
Image: 'C:\Windows\system32\dsac.exe'
filter_main_ms_monitoring_agent:
Image: 'C:\Program Files\Microsoft Monitoring Agent\'
filter_main_powershell:
Image|startswith:
- 'C:\Program Files\PowerShell\7\pwsh.exe'
- 'C:\Program Files\PowerShell\7-preview\pwsh.ex'
- 'C:\Windows\System32\WindowsPowerShell\'
- 'C:\Windows\SysWOW64\WindowsPowerShell\'
condition: selection and not 1 of filter_main_*
falsepositives:
- ADWS is used by a number of legitimate applications that need to interact with Active Directory. These applications should be added to the allow-listing to avoid false positives.
level: medium
Stages and Predicates
Stage 0: condition
selection and not 1 of filter_main_*Stage 1: selection
selection:
Initiated: true
DestinationPort: 9389
Stage 2: not filter_main_*
filter_main_dsac:
Image: 'C:\Windows\system32\dsac.exe'
filter_main_ms_monitoring_agent:
Image: 'C:\Program Files\Microsoft Monitoring Agent\'
filter_main_powershell:
Image|startswith:
- 'C:\Program Files\PowerShell\7\pwsh.exe'
- 'C:\Program Files\PowerShell\7-preview\pwsh.ex'
- 'C:\Windows\System32\WindowsPowerShell\'
- 'C:\Windows\SysWOW64\WindowsPowerShell\'
Exclusions
The rule actively suppresses these predicates.
| Field | Kind | Excluded values | Search |
|---|---|---|---|
Image | eq | C:\Program Files\Microsoft Monitoring Agent\ | excludes:Image field:"Image" value:"C:\Program Files\Microsoft Monitoring Agent\" |
Image | eq | C:\Windows\system32\dsac.exe | excludes:Image field:"Image" value:"C:\Windows\system32\dsac.exe" |
Image | starts_with | C:\Program Files\PowerShell\7-preview\pwsh.ex | excludes:Image field:"Image" value:"C:\Program Files\PowerShell\7-preview\pwsh.ex" |
Image | starts_with | C:\Program Files\PowerShell\7\pwsh.exe | excludes:Image field:"Image" value:"C:\Program Files\PowerShell\7\pwsh.exe" |
Image | starts_with | C:\Windows\SysWOW64\WindowsPowerShell\ | excludes:Image field:"Image" value:"C:\Windows\SysWOW64\WindowsPowerShell\" |
Image | starts_with | C:\Windows\System32\WindowsPowerShell\ | excludes:Image field:"Image" value:"C:\Windows\System32\WindowsPowerShell\" |
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
DestinationPort | eq |
| field:"DestinationPort" kind:eq value:"9389" |
Initiated | eq |
| field:"Initiated" kind:eq value:"true" |