MITRE ATT&CK technique
Exploitation of Remote Services detection rulesT1210
Exploitation of Remote Services (T1210) is a MITRE ATT&CK technique in the Lateral Movement tactic. This page lists the 15 community-maintained Sigma detection rules in the library mapped to T1210 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, zeek.
Tactic
Audit CVE Event
criticalDetects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited. MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability. Unfortunately, that is about the only instance of CVEs being written to this log.
windows
WannaCry Ransomware Activity
criticalDetects WannaCry ransomware activity
windows · process_creation
Zerologon Exploitation Using Well-known Tools
criticalThis rule is designed to detect attempts to exploit Zerologon (CVE-2020-1472) vulnerability using mimikatz zerologon module or other exploits from machine with "kali" hostname.
windows
Exploitation Attempt Of CVE-2020-1472 - Execution of ZeroLogon PoC
highDetects the execution of the commonly used ZeroLogon PoC executable.
windows · process_creation
Exploitation Attempt Of CVE-2023-46214 Using Public POC Code
highDetects exploitation attempt of CVE-2023-46214, a remote code execution (RCE) in Splunk Enterprise through insecure XML parsing using known public proof of concept code
webserver
HackTool - SharpWSUS/WSUSpendu Execution
highDetects the execution of SharpWSUS or WSUSpendu, utilities that allow for lateral movement through WSUS. Windows Server Update Services (WSUS) is a critical component of Windows systems and is frequently configured in a way that allows an attacker to circumvent internal networking limitations.
windows · process_creation
OMIGOD HTTP No Authentication RCE - CVE-2021-38647
highDetects the exploitation of OMIGOD (CVE-2021-38647) which allows remote execute (RCE) commands as root with just a single unauthenticated HTTP request. Verify, successful, exploitation by viewing the HTTP client (request) body to see what was passed to the server (using PCAP). Within the client body is where the code execution would occur. Additionally, check the endpoint logs to see if suspicious commands or activity occurred within the timeframe of this HTTP request.
zeek
Possible Exploitation of Exchange RCE CVE-2021-42321
highDetects log entries that appear in exploitation attempts against MS Exchange RCE CVE-2021-42321
windows
Scanner PoC for CVE-2019-0708 RDP RCE Vuln
highDetects the use of a scanner by zerosum0x0 that discovers targets vulnerable to CVE-2019-0708 RDP RCE aka BlueKeep
windows
Terminal Service Process Spawn
highDetects a process spawned by the terminal service server process (this could be an indicator for an exploitation of CVE-2019-0708)
windows · process_creation
Apache Threading Error
mediumDetects an issue in apache logs that reports threading related errors
Potential CVE-2023-46214 Exploitation Attempt
mediumDetects potential exploitation of CVE-2023-46214, a remote code execution (RCE) in Splunk Enterprise through insecure XML parsing
webserver
Potential RDP Exploit CVE-2019-0708
mediumDetect suspicious error on protocol RDP, potential CVE-2019-0708
windows
Suspicious SysAidServer Child
mediumDetects suspicious child processes of SysAidServer (as seen in MERCURY threat actor intrusions)
windows · process_creation
DNS Query Request By QuickAssist.EXE
lowDetects DNS queries initiated by "QuickAssist.exe" to Microsoft Quick Assist primary endpoint that is used to establish a session.
windows · dns_query