Detection rules › Sigma

Suspicious Computer Machine Password by PowerShell

Status
test
Severity
medium
Log source
category ps_module, product windows
Author
frack113
Source
github.com/SigmaHQ/sigma

The Reset-ComputerMachinePassword cmdlet changes the computer account password that the computers use to authenticate to the domain controllers in the domain. You can use it to reset the password of the local computer.

Known false positives

  • Administrator PowerShell scripts

MITRE ATT&CK coverage

TacticTechniques
Initial Access
Persistence
Privilege Escalation
Stealth

Telemetry coverage

Rule body

title: Suspicious Computer Machine Password by PowerShell
id: e3818659-5016-4811-a73c-dde4679169d2
status: test
description: |
    The Reset-ComputerMachinePassword cmdlet changes the computer account password that the computers use to authenticate to the domain controllers in the domain.
    You can use it to reset the password of the local computer.
references:
    - https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/reset-computermachinepassword?view=powershell-5.1
    - https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/
author: frack113
date: 2022-02-21
tags:
    - attack.privilege-escalation
    - attack.persistence
    - attack.initial-access
    - attack.stealth
    - attack.t1078
logsource:
    product: windows
    category: ps_module
    definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
    selection:
        ContextInfo|contains: 'Reset-ComputerMachinePassword'
    condition: selection
falsepositives:
    - Administrator PowerShell scripts
level: medium

Stages and Predicates

Stage 0: condition

selection

Stage 1: selection

selection:
    ContextInfo|contains: 'Reset-ComputerMachinePassword'

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
ContextInfomatch
  • Reset-ComputerMachinePassword
field:"ContextInfo" kind:match value:"Reset-ComputerMachinePassword"