Potential Pass the Hash Activity


Description

Detects the attack technique pass the hash which is used to move laterally inside the network

Query · sigma

selection:
  EventID:
  - 4624
  - 4625
  LogonType: 3
  LogonProcessName: NtLmSsp
  WorkstationName|expand: '%Workstations%'
  ComputerName|expand: '%Workstations%'
filter:
  TargetUserName: ANONYMOUS LOGON
condition: selection and not filter

Known false positives

  • Administrator activity
Raw source Potential Pass the Hash Activity · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: Potential Pass the Hash Activity
id: f8d98d6c-7a07-4d74-b064-dd4a3c244528
status: test
description: Detects the attack technique pass the hash which is used to move laterally inside the network
references:
    - https://github.com/nsacyber/Event-Forwarding-Guidance/tree/6e92d622fa33da911f79e7633da4263d632f9624/Events
author: Ilias el Matani (rule), The Information Assurance Directorate at the NSA (method)
date: 2017-03-08
modified: 2023-12-15
tags:
    - attack.lateral-movement
    - attack.t1550.002
    - car.2016-04-004
logsource:
    product: windows
    service: security
    definition: The successful use of PtH for lateral movement between workstations would trigger event ID 4624, a failed logon attempt would trigger an event ID 4625
detection:
    selection:
        EventID:
            - 4624
            - 4625
        LogonType: 3
        LogonProcessName: 'NtLmSsp'
        WorkstationName|expand: '%Workstations%'
        ComputerName|expand: '%Workstations%'
    filter:
        TargetUserName: 'ANONYMOUS LOGON'
    condition: selection and not filter
falsepositives:
    - Administrator activity
level: medium

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.