Sagan critical stable other
[WINDOWS-SECURITY] Credential Access - Copy NTDS file
[WINDOWS-SECURITY] Credential Access - Copy NTDS file
Detection Logic
alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SECURITY] Credential Access - Copy NTDS file"; program:*Sysmon*
| *Security*; event_id:1,4688; content:"cmd"; nocase; content:"copy"; nocase; content:"ntds.dit"; nocase; reference:url,www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a; classtype:trojan-activity; sid:5013876; rev:1; metadata:deployment Endpoint,affected_product NONE,affected_version NONE,mitigation NONE,deprecation_reason NONE,tag NONE, created_at 2023_06_12, updated_at 2023_06_12, mitre_tactic_id TA0006, mitre_technique_id T1003.003;) Field Validations
Loading…
Comments (0)
Loading comments...