Detection rules › Sigma

Anonymous access performed to multiple targets

Status
experimental
Severity
high
Time window
15m
Log source
product windows, service security
Author
mdecrevoisier
Source
github.com/mdecrevoisier/SIGMA-detection-rules

Detects scenarios where an attacker would attempt to enumerate hosts and collect relevant information using anonymous access. Vulnerability scanners, enumeration software or tool like CrackMapexec may generate such behavior.

Known false positives

  • VAS scanners, pentest

MITRE ATT&CK coverage

TacticTechniques
Discovery

Telemetry coverage

Rule body

title: Anonymous access performed to multiple targets
description: Detects scenarios where an attacker would attempt to enumerate hosts and collect relevant information using anonymous access. Vulnerability scanners, enumeration software or tool like CrackMapexec may generate such behavior.
references:
- https://medium.com/@Shorty420/enumerating-ad-98e0821c4c78
- https://book.hacktricks.xyz/pentesting/pentesting-smb
- https://0xdf.gitlab.io/2018/12/02/pwk-notes-smb-enumeration-checklist-update1.html
tags:
- attack.discovery
- attack.t1046
author: mdecrevoisier
status: experimental
logsource:
  product: windows
  service: security
detection:
  selection:
    EventID: 4624
    TargetUserSid: S-1-5-7 # ANONYMOUS LOGON
    LogonType: 3
    #AuthenticationPackageName: NTLM
  filter:
    IpAddress:
      - '%vulnerability_scanners%'
      - '127.0.0.1'
      - '::1'
  condition: selection and not filter | count(Computer) by IpAddress > 20 # Count of many computer are reporting connection attemps from a single source IP
  timeframe: 15m
falsepositives:
- VAS scanners, pentest
level: high

Stages and Predicates

Stage 0: condition

selection and not filter | count(Computer) by IpAddress > 20 # Count of many computer are reporting connection attemps from a single source IP

Stage 1: selection

selection:
  EventID: 4624
  TargetUserSid: S-1-5-7
  LogonType: 3
Threshold
> 20

Stage 2: not filter

filter:
  IpAddress:
    - '%vulnerability_scanners%'
    - '127.0.0.1'
    - '::1'

Exclusions

The rule actively suppresses these predicates.

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
LogonTypeeq
  • 3 corpus 41 (splunk 13, sigma 12, elastic 9, kusto 7)
field:"LogonType" kind:eq value:"3"
TargetUserSideq
  • S-1-5-7 corpus 3 (sigma 3)
field:"TargetUserSid" kind:eq value:"S-1-5-7"