MITRE ATT&CK technique
Password Policy Discovery detection rulesT1201
Password Policy Discovery (T1201) is a MITRE ATT&CK technique in the Discovery tactic. This page lists the 6 community-maintained Sigma detection rules in the library mapped to T1201 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, cisco, linux.
HackTool - CrackMapExec Execution
highThis rule detect common flag combinations used by CrackMapExec in order to detect its use even if the binary has been replaced.
windows · process_creation
Password Policy Enumerated
mediumDetects when the password policy is enumerated.
windows
Cisco Discovery
lowFind information about network devices that is not stored in config files
cisco
Net.EXE Execution
lowDetects execution of "Net.EXE".
windows · process_creation
Password Policy Discovery - Linux
lowDetects password policy discovery commands
linux
Password Policy Discovery With Get-AdDefaultDomainPasswordPolicy
lowDetetcts PowerShell activity in which Get-Addefaultdomainpasswordpolicy is used to get the default password policy for an Active Directory domain.
windows · ps_script