Sagan high stable other

[WINDOWS-POWERSHELL] Registry Query for WDigest UseLogonCredential

[WINDOWS-POWERSHELL] Registry Query for WDigest UseLogonCredential

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-POWERSHELL] Registry Query for WDigest UseLogonCredential"; program: *PowerShell*; json_map:"event_id",".EventID"; json_map:"message",".RenderedDescription"; event_id:400,800,4103,4104; content:"reg query"; content:"HKLM\\"; within:10; content:"WDigest"; nocase; content:"UseLogonCredential"; nocase; within:30; reference:url,thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/; reference:url,github.com/The-DFIR-Report/Sigma-Rules/blob/75260568a7ffe61b2458ca05f6f25914efb44337/Enable WDigest using PowerShell; classtype:suspicious-command; sid:5009358; metadata: created_on 2022_11_22, old_sid 5007145; rev:1;)

Field Validations

Loading…

Comments (0)

Loading comments...