MITRE ATT&CK technique
Exploitation for Credential Access detection rulesT1212
Exploitation for Credential Access (T1212) is a MITRE ATT&CK technique in the Credential Access tactic. This page lists the 5 community-maintained Sigma detection rules in the library mapped to T1212 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, linux.
Tactic
Audit CVE Event
criticalDetects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited. MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability. Unfortunately, that is about the only instance of CVEs being written to this log.
windows
GALLIUM IOCs
highDetects artifacts associated with GALLIUM cyber espionage group as reported by Microsoft Threat Intelligence Center in the December 2019 report.
windows · process_creation
Guacamole Two Users Sharing Session Anomaly
highDetects suspicious session with two users present
linux
Kerberos Manipulation
highDetects failed Kerberos TGT issue operation. This can be a sign of manipulations of TGT messages by an attacker.
windows
Suspicious NTLM Authentication on the Printer Spooler Service
highDetects a privilege elevation attempt by coercing NTLM authentication on the Printer Spooler service
windows · process_creation