Hayabusa high test sigma

Possible Impacket SecretDump Remote Activity

Detect AD credential dumping using impacket secretdump HKTL

View Source

Detection Logic

{
  "security": {
    "Channel": "Security"
  },
  "selection": {
    "EventID": 5145,
    "ShareName": "\\\\\\\\\\*\\\\ADMIN$",
    "RelativeTargetName
| contains
| all": [
      "SYSTEM32\\",
      ".tmp"
    ]
  },
  "condition": "security and selection"
}

False Positives

  • Unknown

Field Validations

Loading…

Comments (0)

Loading comments...