hacktool_mimikatz_execution
Description
Detection well-known mimikatz command line arguments
Query · yara_l
events:
$process.metadata.event_type = "PROCESS_LAUNCH"
(
strings.contains(strings.to_lower($process.target.process.command_line), "dumpcreds") or
strings.contains(strings.to_lower($process.target.process.command_line), "mimikatz") or
strings.contains(strings.to_lower($process.target.process.command_line), "::aadcookie") or
strings.contains(strings.to_lower($process.target.process.command_line), "::detours") or
strings.contains(strings.to_lower($process.target.process.command_line), "::memssp") or
strings.contains(strings.to_lower($process.target.process.command_line), "::mflt") or
strings.contains(strings.to_lower($process.target.process.command_line), "::ncroutemon") or
strings.contains(strings.to_lower($process.target.process.command_line), "::ngcsign") or
strings.contains(strings.to_lower($process.target.process.command_line), "::printnightmare") or
strings.contains(strings.to_lower($process.target.process.command_line), "::skeleton") or
strings.contains(strings.to_lower($process.target.process.command_line), "::preshutdown") or
strings.contains(strings.to_lower($process.target.process.command_line), "::mstsc") or
strings.contains(strings.to_lower($process.target.process.command_line), "::multirdp") or
strings.contains(strings.to_lower($process.target.process.command_line), "rpc::") or
strings.contains(strings.to_lower($process.target.process.command_line), "token::") or
strings.contains(strings.to_lower($process.target.process.command_line), "crypto::") or
strings.contains(strings.to_lower($process.target.process.command_line), "dpapi::") or
strings.contains(strings.to_lower($process.target.process.command_line), "sekurlsa::") or
strings.contains(strings.to_lower($process.target.process.command_line), "kerberos::") or
strings.contains(strings.to_lower($process.target.process.command_line), "lsadump::") or
strings.contains(strings.to_lower($process.target.process.command_line), "privilege::") or
strings.contains(strings.to_lower($process.target.process.command_line), "process::") or
strings.contains(strings.to_lower($process.target.process.command_line), "vault::")
)
$process.principal.hostname = $hostname
match:
$hostname over 5m
outcome:
//example usage of specifying test user and hostname to adjust risk score
$risk_score = max(if($process.principal.user.userid = "user" and $process.principal.hostname = "hostname", 0, 15))
$principal_process_pid = array_distinct($process.principal.process.pid)
$principal_process_command_line = array_distinct($process.principal.process.command_line)
$principal_process_file_sha256 = array_distinct($process.principal.process.file.sha256)
$principal_process_file_full_path = array_distinct($process.principal.process.file.full_path)
$principal_process_product_specfic_process_id = array_distinct($process.principal.process.product_specific_process_id)
$principal_process_parent_process_product_specfic_process_id = array_distinct($process.principal.process.parent_process.product_specific_process_id)
$target_process_pid = array_distinct($process.target.process.pid)
$target_process_command_line = array_distinct($process.target.process.command_line)
$target_process_file_sha256 = array_distinct($process.target.process.file.sha256)
$target_process_file_full_path = array_distinct($process.target.process.file.full_path)
$target_process_product_specfic_process_id = array_distinct($process.target.process.product_specific_process_id)
$principal_user_userid = array_distinct($process.principal.user.userid)
$log_type = array_distinct(strings.concat($process.metadata.log_type,"/",$process.metadata.product_event_type))
condition:
$process