Detection rules › Sigma
Anonymous access performed to multiple targets
Detects scenarios where an attacker would attempt to enumerate hosts and collect relevant information using anonymous access. Vulnerability scanners, enumeration software or tool like CrackMapexec may generate such behavior.
Known false positives
- VAS scanners, pentest
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Discovery |
Telemetry coverage
| Provider | Record / event type |
|---|---|
| Security-Auditing | Event ID 4624: An account was successfully logged on. |
Rule body
title: Anonymous access performed to multiple targets
description: Detects scenarios where an attacker would attempt to enumerate hosts and collect relevant information using anonymous access. Vulnerability scanners, enumeration software or tool like CrackMapexec may generate such behavior.
references:
- https://medium.com/@Shorty420/enumerating-ad-98e0821c4c78
- https://book.hacktricks.xyz/pentesting/pentesting-smb
- https://0xdf.gitlab.io/2018/12/02/pwk-notes-smb-enumeration-checklist-update1.html
tags:
- attack.discovery
- attack.t1046
author: mdecrevoisier
status: experimental
logsource:
product: windows
service: security
detection:
selection:
EventID: 4624
TargetUserSid: S-1-5-7 # ANONYMOUS LOGON
LogonType: 3
#AuthenticationPackageName: NTLM
filter:
IpAddress:
- '%vulnerability_scanners%'
- '127.0.0.1'
- '::1'
condition: selection and not filter | count(Computer) by IpAddress > 20 # Count of many computer are reporting connection attemps from a single source IP
timeframe: 15m
falsepositives:
- VAS scanners, pentest
level: high
Stages and Predicates
Stage 0: condition
selection and not filter | count(Computer) by IpAddress > 20 # Count of many computer are reporting connection attemps from a single source IPStage 1: selection
selection:
EventID: 4624
TargetUserSid: S-1-5-7
LogonType: 3
Stage 2: not filter
filter:
IpAddress:
- '%vulnerability_scanners%'
- '127.0.0.1'
- '::1'
Exclusions
The rule actively suppresses these predicates.
| Field | Kind | Excluded values | Search |
|---|---|---|---|
IpAddress | eq | %vulnerability_scanners% | excludes:IpAddress field:"IpAddress" value:"%vulnerability_scanners%" |
IpAddress | eq | 127.0.0.1 | excludes:IpAddress field:"IpAddress" value:"127.0.0.1" |
IpAddress | eq | ::1 | excludes:IpAddress field:"IpAddress" value:"::1" |
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
LogonType | eq |
| field:"LogonType" kind:eq value:"3" |
TargetUserSid | eq |
| field:"TargetUserSid" kind:eq value:"S-1-5-7" |