Sigma Rule Library

Potential Pass the Hash Activity

Detects the attack technique pass the hash which is used to move laterally inside the network

View on GitHubOpen raw file

Detection logic

selection

EventID:
  - 4624
  - 4625
LogonType: 3
LogonProcessName: NtLmSsp
WorkstationName|expand: "%Workstations%"
ComputerName|expand: "%Workstations%"

filter

TargetUserName: ANONYMOUS LOGON

Condition

selection and not filter

Raw YAML

title: Potential Pass the Hash Activity
id: f8d98d6c-7a07-4d74-b064-dd4a3c244528
status: test
description: Detects the attack technique pass the hash which is used to move laterally inside the network
references:
    - https://github.com/nsacyber/Event-Forwarding-Guidance/tree/6e92d622fa33da911f79e7633da4263d632f9624/Events
author: Ilias el Matani (rule), The Information Assurance Directorate at the NSA (method)
date: 2017-03-08
modified: 2023-12-15
tags:
    - attack.lateral-movement
    - attack.t1550.002
    - car.2016-04-004
logsource:
    product: windows
    service: security
    definition: The successful use of PtH for lateral movement between workstations would trigger event ID 4624, a failed logon attempt would trigger an event ID 4625
detection:
    selection:
        EventID:
            - 4624
            - 4625
        LogonType: 3
        LogonProcessName: 'NtLmSsp'
        WorkstationName|expand: '%Workstations%'
        ComputerName|expand: '%Workstations%'
    filter:
        TargetUserName: 'ANONYMOUS LOGON'
    condition: selection and not filter
falsepositives:
    - Administrator activity
level: medium

False positives

  • Administrator activity

References

Similar rules