Detection rules › Sigma

Windows native Pktmon sniffer abuse

Status
experimental
Severity
medium
Log source
category process_creation, product windows
Author
mdecrevoisier
Source
github.com/mdecrevoisier/SIGMA-detection-rules

Detects scenarios where an attacker use the Windows sniffer Pktmon in order to capture sensitive information or credentials.

Known false positives

  • Administrator network troubleshooting

MITRE ATT&CK coverage

TacticTechniques
Credential Access

Telemetry coverage

Rule body

title: Windows native Pktmon sniffer abuse
description: Detects scenarios where an attacker use the Windows sniffer Pktmon in order to capture sensitive information or credentials.
references:
- https://github.com/mdecrevoisier/EVTX-to-MITRE-Attack/tree/master/TA0006-Credential%20Access/T1040-Traffic%20sniffing
- https://dev.to/qainsights/windows-network-sniffer-pktmon-2576
- https://docs.microsoft.com/en-us/windows-server/networking/technologies/pktmon/pktmon
tags:
- attack.credential_access
- attack.t1040 # Network Sniffing 
author: mdecrevoisier
status: experimental
logsource:
  product: windows
  category: process_creation
detection:
  selection:
    NewProcessName|endswith: '\PktMon.exe'
    CommandLine|contains|all: # full command : 'pktmon filter add -p 80'
      - pktmon
      - filter
      - add
  condition: selection
falsepositives:
- Administrator network troubleshooting
level: medium

Stages and Predicates

Stage 0: condition

selection

Stage 1: selection

selection:
  NewProcessName|endswith: '\PktMon.exe'
  CommandLine|contains|all:
    - pktmon
    - filter
    - add

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
CommandLinematch
  • add corpus 34 (sigma 26, splunk 4, chronicle 2, kusto 2)
  • filter
  • pktmon
field:"CommandLine" kind:match
NewProcessNameends_with
  • \PktMon.exe corpus 2 (sigma 2)
field:"Image" kind:ends_with value:"\PktMon.exe"