Windows_Hacktool_WinPEAS_ng_413caa6b
Description
WinPEAS detection based on the dotNet binary, event module
Query · yara
strings:
$win_0 = "Interesting Events information" ascii wide
$win_1 = "PowerShell events" ascii wide
$win_2 = "Created (UTC)" ascii wide
$win_3 = "Printing Account Logon Events" ascii wide
$win_4 = "Subject User Name" ascii wide
$win_5 = "Target User Name" ascii wide
$win_6 = "NTLM relay might be possible" ascii wide
$win_7 = "You can obtain NetNTLMv2" ascii wide
$win_8 = "The following users have authenticated" ascii wide
$win_9 = "You must be an administrator" ascii wide
condition:
5 of them