mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 10:13:57 +00:00
Merge pull request #28 from neu5ron/patch-1
Create win_alert_enable_weak_encryption.yml
This commit is contained in:
commit
c5b19d5661
23
rules/windows/builtin/win_alert_enable_weak_encryption.yml
Normal file
23
rules/windows/builtin/win_alert_enable_weak_encryption.yml
Normal file
@ -0,0 +1,23 @@
|
||||
title: Detects Enabling of Weak Encryption and Kerberoast
|
||||
description: Detects scenario where weak encryption is enabled for a user profile which could be used for hash/password cracking.
|
||||
reference:
|
||||
- https://adsecurity.org/?p=2053
|
||||
- https://www.harmj0y.net/blog/activedirectory/roasting-as-reps/
|
||||
author: @neu5ron
|
||||
logsource:
|
||||
product: windows
|
||||
service: security
|
||||
description: 'Requirements: Audit Policy : Account Management > Audit User Account Management, Group Policy : Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Account Management\Audit User Account Management'
|
||||
detection:
|
||||
selection:
|
||||
EventID: 4738
|
||||
keywords:
|
||||
- 'DES'
|
||||
- 'Preauth'
|
||||
- 'Encrypted'
|
||||
filters:
|
||||
- 'Enabled'
|
||||
condition: selection and keywords and filters
|
||||
falsepositives:
|
||||
- Unknown
|
||||
level: high
|
Loading…
Reference in New Issue
Block a user