Detection rules › Sigma

Potential Discovery Activity Via Dnscmd.EXE

Status
test
Severity
medium
Log source
product windows, category process_creation
Author
@gott_cyber
Source
github.com/SigmaHQ/sigma

Detects an attempt to leverage dnscmd.exe to enumerate the DNS zones of a domain. DNS zones used to host the DNS records for a particular domain.

MITRE ATT&CK coverage

TacticTechniques
ExecutionNo specific technique
DiscoveryNo specific technique

Event coverage

Rule body yaml

title: Potential Discovery Activity Via Dnscmd.EXE
id: b6457d63-d2a2-4e29-859d-4e7affc153d1
status: test
description: Detects an attempt to leverage dnscmd.exe to enumerate the DNS zones of a domain. DNS zones used to host the DNS records for a particular domain.
references:
    - https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/dnscmd
    - https://learn.microsoft.com/en-us/azure/dns/dns-zones-records
    - https://lolbas-project.github.io/lolbas/Binaries/Dnscmd/
author: '@gott_cyber'
date: 2022-07-31
modified: 2023-02-04
tags:
    - attack.discovery
    - attack.execution
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        Image|endswith: '\dnscmd.exe'
    selection_cli:
        CommandLine|contains:
            - '/enumrecords'
            - '/enumzones'
            - '/ZonePrint'
            - '/info'
    condition: all of selection_*
falsepositives:
    - Legitimate administration use
level: medium

Stages and Predicates

Stage 0: condition

all of selection_*

Stage 1: selection_img

selection_img:
    Image|endswith: '\dnscmd.exe'

Stage 2: selection_cli

selection_cli:
    CommandLine|contains:
        - '/enumrecords'
        - '/enumzones'
        - '/ZonePrint'
        - '/info'

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
CommandLinematch
  • /ZonePrint
  • /enumrecords
  • /enumzones
  • /info
Imageends_with
  • \dnscmd.exe corpus 3 (sigma 3)