Elastic Defend high stable eql

Suspicious NullSessionPipe Registry Modification

Identifies NullSessionPipe registry modifications that specify pipe names that can be accessed anonymously. This could be indicative of adversary lateral movement preparation by making the added pipe accessible to remote systems.

View Source

Detection Logic

registry where
 event.action == "modification" and 
 registry.path : "HKLM\\SYSTEM\\*ControlSet*\\services\\LanmanServer\\Parameters\\NullSessionPipes" and 
 not user.id : ("S-1-5-18", "S-1-5-19", "S-1-5-20") and 
 registry.data.strings : "*?*" and process.executable : "?:\\*" and
 not process.executable : ("?:\\Program Files\\*.exe",
                           "?:\\Program Files (x86)\\*.exe",
                           "?:\\Windows\\regedit.exe",
                           "?:\\Windows\\System32\\drivers\\RivetNetworks\\Killer\\*.exe",
                           "?:\\Windows\\System32\\svchost.exe",
                           "?:\\Windows\\System32\\lsass.exe",
                           "?:\\Windows\\System32\\msiexec.exe",
                           "?:\\Windows\\System32\\services.exe",
                           "?:\\Windows\\System32\\PDR23PM_SV64.EXE", 
                           "?:\\Windows\\System32\\PLPOUSVR.exe")

Field Validations

Loading…

Comments (0)

Loading comments...