Suspicious Remote Logon with Explicit Credentials
Description
Detects suspicious processes logging on with explicit credentials
Query · sigma
selection: EventID: 4648 ProcessName|endswith: - \cmd.exe - \powershell.exe - \pwsh.exe - \winrs.exe - \wmic.exe - \net.exe - \net1.exe - \reg.exe filter1: TargetServerName: localhost filter2: SubjectUserName|endswith: $ TargetUserName|endswith: $ condition: selection and not 1 of filter*
Known false positives
- Administrators that use the RunAS command or scheduled tasks