mirror of
https://github.com/iimp0ster/detection-chokepoints
synced 2026-08-09 12:41:00 +00:00
Adds scripts/validate_schema.py and a validate-data.yml PR gate that checks every chokepoints/*/*.yml against schema/chokepoint-schema.yml: required fields, enum values, UUIDv4/ISO-date/MITRE-id formats, tactic folder consistency, and that referenced Sigma paths exist on disk. (Replaces the validate_schema.py that cp-drafter referenced but was never created.) Validator tolerates the authored conventions for Variations.Status and ExpectedFPRate (leading token + detail). Fixes surfaced by the validator/link audit: - 2 invalid Ids regenerated as real UUIDv4 (ransomware-service- manipulation, remote-execution-tools) - 4 dead reference citations repaired (Proofpoint moved URL; Trustwave via Wayback; Metasploit psexec -> GitHub docs; BleepingComputer had a wrong slug -> correct article) Adds scripts/check_links.py — advisory external-link sweep (not a CI gate; external links flake). Buckets BROKEN vs BLOCKED vs OK so API endpoints and bot-blocked blogs are not mistaken for rot. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
479 lines
25 KiB
YAML
479 lines
25 KiB
YAML
Name: Remote Execution Tools (HackTools)
|
|
Id: 36c84325-2c23-4511-8d69-23b94256f846
|
|
MitreIds:
|
|
- T1021.002
|
|
- T1021.003
|
|
- T1021.006
|
|
- T1047
|
|
- T1053.005
|
|
- T1569.002
|
|
Tactics:
|
|
- Lateral Movement
|
|
- Execution
|
|
Techniques:
|
|
- 'Remote Services: SMB/Windows Admin Shares'
|
|
- 'Remote Services: Distributed Component Object Model'
|
|
- 'Remote Services: Windows Remote Management'
|
|
- Windows Management Instrumentation
|
|
- 'Scheduled Task/Job: Scheduled Task'
|
|
- 'System Services: Service Execution'
|
|
DetectionPriority: HIGH
|
|
ThreatPrevalence: HIGH
|
|
DetectionDifficulty: MEDIUM
|
|
Description: 'Offensive security tools (Impacket, NetExec, CrackMapExec, Evil-WinRM) used for remote code execution across
|
|
Windows environments. These frameworks wrap legitimate Windows protocols (SMB, WMI, WinRM, RPC) to execute code on remote
|
|
systems using valid admin credentials. Despite tool diversity, the chokepoint is invariant: valid admin credentials, network
|
|
access to target ports, and a remote execution primitive (service creation, WMI process, scheduled task) are always required.
|
|
|
|
'
|
|
LastUpdated: '2026-03-07'
|
|
Author: '@iimp0ster'
|
|
Variations:
|
|
- Name: Impacket
|
|
FirstSeen: '2015'
|
|
Status: Active
|
|
SourceURL: https://github.com/fortra/impacket
|
|
NotesShort: Python suite with psexec/wmiexec/atexec/dcomexec modules; rdp_shadow added January 2025
|
|
Notes: 'Python suite with multiple execution modules: psexec.py (SMB service creation), smbexec.py (SMB + scheduled tasks),
|
|
wmiexec.py (WMI process creation), atexec.py (Task Scheduler), dcomexec.py (DCOM), rdp_shadow.py (RDP session hijacking,
|
|
added 2025-01)
|
|
|
|
'
|
|
VariantId: impacket
|
|
Command:
|
|
Invocation: "python3 psexec.py domain/admin:Password123@192.168.1.10\npython3 wmiexec.py domain/admin:Password123@192.168.1.10\npython3 psexec.py -hashes :aad3b435b51404eeaad3b435b51404ee domain/admin@192.168.1.10"
|
|
Context: 'Python suite with psexec (SMB service), wmiexec (WMI), smbexec (temp service), atexec (Task Scheduler). psexec creates a service on the remote host via IPC$/svcctl.'
|
|
Artifacts:
|
|
- 'Security EID 4624: Network logon (Type 3) with admin account'
|
|
- 'Security EID 4672: Special privileges assigned'
|
|
- 'System EID 7045: Service installed (random name)'
|
|
- 'Security EID 5145: IPC$ and ADMIN$ share access'
|
|
- 'Sysmon EID 1: services.exe or wmiprvse.exe → cmd.exe'
|
|
ChokepointMapping: 'SMB auth (4624 Type 3) → IPC$/svcctl → service created (7045) → services.exe spawns cmd.exe'
|
|
- Name: CrackMapExec
|
|
FirstSeen: '2016'
|
|
Status: Legacy
|
|
SourceURL: https://github.com/byt3bl33d3r/CrackMapExec
|
|
NotesShort: Archived December 2023; superseded by NetExec. CME-specific signatures now stale
|
|
Notes: Multi-protocol framework covering SMB, WMI, WinRM, MSSQL; original repository archived by maintainer on December
|
|
6, 2023 (read-only); superseded by NetExec. Defenders should not expect CME-specific signatures to receive community
|
|
updates
|
|
VariantId: crackmapexec
|
|
Command:
|
|
Invocation: "cme smb 192.168.1.0/24 -u admin -p Password123 --exec-method smbexec -x \"whoami\"\ncme smb 192.168.1.0/24 -u admin -H <hash> --exec-method wmiexec -x \"whoami\"\ncme winrm 192.168.1.10 -u admin -p Password123 -x \"whoami\""
|
|
Context: 'Multi-protocol framework (archived Dec 2023, superseded by NetExec). Binary was crackmapexec or cme.'
|
|
Artifacts:
|
|
- 'Security EID 4624: Multiple Type 3 logons from same source IP in short window'
|
|
- 'Security EID 4625: Failed logons (credential spraying)'
|
|
- 'Sysmon EID 1: services.exe or wmiprvse.exe → cmd.exe across multiple hosts'
|
|
- 'Sysmon EID 3: Single source IP → multiple internal destinations on 445/135/5985'
|
|
ChokepointMapping: 'Credential spray (4624/4625 from single IP) → exec method per host → lateral spread pattern'
|
|
- Name: NetExec
|
|
FirstSeen: '2023'
|
|
Status: Active
|
|
SourceURL: https://github.com/Pennyw0rth/NetExec
|
|
NotesShort: Active CrackMapExec fork; adds LDAP, SSH, and improved OPSEC features
|
|
Notes: Active CrackMapExec fork; adds LDAP, SSH, improved OPSEC features
|
|
VariantId: netexec
|
|
Command:
|
|
Invocation: "nxc smb 192.168.1.0/24 -u admin -p Password123 --exec-method smbexec -x \"whoami\"\nnxc smb 192.168.1.0/24 -u admin -H <hash> --exec-method wmiexec -x \"whoami\"\nnxc winrm 192.168.1.10 -u admin -p Password123 -x \"whoami\""
|
|
Context: 'Multi-protocol framework. Spray credentials across subnets. Supports SMB, WMI, WinRM, LDAP, SSH. Active fork of archived CrackMapExec.'
|
|
Artifacts:
|
|
- 'Security EID 4624: Multiple Type 3 logons from same source IP in short window'
|
|
- 'Security EID 4625: Failed logons (credential spraying)'
|
|
- 'Sysmon EID 1: services.exe or wmiprvse.exe → cmd.exe across multiple hosts'
|
|
- 'Sysmon EID 3: Single source IP → multiple internal destinations on 445/135/5985'
|
|
ChokepointMapping: 'Credential spray (4624/4625 from single IP) → exec method per host → lateral spread pattern'
|
|
- Name: Evil-WinRM
|
|
FirstSeen: '2019'
|
|
Status: Active
|
|
SourceURL: https://github.com/Hackplayers/evil-winrm
|
|
NotesShort: Dedicated WinRM exploitation tool targeting port 5985/5986
|
|
Notes: Dedicated WinRM exploitation tool; targets port 5985/5986
|
|
VariantId: evil-winrm
|
|
Command:
|
|
Invocation: "evil-winrm -i 192.168.1.10 -u admin -p Password123\nevil-winrm -i 192.168.1.10 -u admin -H aad3b435b51404eeaad3b435b51404ee"
|
|
Context: 'Dedicated WinRM exploitation tool. Uses port 5985/5986. Provides PowerShell session on target. Supports pass-the-hash.'
|
|
Artifacts:
|
|
- 'Security EID 4624: Network logon (Type 3) on port 5985/5986'
|
|
- 'Sysmon EID 1: wsmprovhost.exe → powershell.exe'
|
|
- 'Windows-WinRM/Operational: Session created'
|
|
- 'Sysmon EID 3: Inbound connection on 5985/5986'
|
|
ChokepointMapping: 'WinRM auth (5985) → wsmprovhost.exe spawns powershell.exe → command execution'
|
|
- Name: Metasploit psexec
|
|
FirstSeen: '2007'
|
|
Status: Active
|
|
SourceURL: https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/exploit/windows/smb/psexec.md
|
|
NotesShort: Original PsExec-style SMB execution via Metasploit framework
|
|
Notes: Original PsExec-style SMB execution via Metasploit framework
|
|
VariantId: metasploit-psexec
|
|
Command:
|
|
Invocation: "use exploit/windows/smb/psexec\nset RHOSTS 192.168.1.10\nset SMBUser admin\nset SMBPass Password123\nset PAYLOAD windows/meterpreter/reverse_tcp\nexploit"
|
|
Context: 'Original psexec in Metasploit. Creates service, uploads payload via ADMIN$ share, executes via service start.'
|
|
Artifacts:
|
|
- 'Security EID 4624: Network logon (Type 3)'
|
|
- 'System EID 7045: Service installed with random name'
|
|
- 'Security EID 5145: ADMIN$ share access'
|
|
- 'Sysmon EID 1: services.exe → rundll32.exe or payload'
|
|
- 'Sysmon EID 11: Payload written to ADMIN$ share'
|
|
ChokepointMapping: 'SMB auth → ADMIN$ share write → service created (random name) → Meterpreter callback'
|
|
- Name: Sliver
|
|
FirstSeen: '2020'
|
|
Status: Active
|
|
SourceURL: https://github.com/BishopFox/sliver
|
|
NotesShort: Open-source C2 widely adopted by nation-state and ransomware actors as Cobalt Strike alternative
|
|
Notes: Open-source C2 framework widely adopted by nation-state and ransomware actors as a Cobalt Strike alternative; built-in
|
|
lateral movement over SMB/WMI using the same execution primitives this chokepoint detects; used by threat actors following
|
|
Fortra's crackdown on pirated Cobalt Strike licenses
|
|
VariantId: sliver
|
|
Command:
|
|
Invocation: "sliver > psexec -t <target> -s <service_name> -p <profile>\n# Or via WMI:\nsliver > execute-assembly -t <target> -- wmiexec\n# Implant types: session (interactive), beacon (async)\n# Transports: named pipes, mTLS, WireGuard, HTTPS, DNS"
|
|
Context: 'Open-source C2 by BishopFox. Growing adoption as CobaltStrike alternative. Implants are cross-compiled Go binaries.'
|
|
Artifacts:
|
|
- 'Security EID 4624: Network logon (Type 3)'
|
|
- 'System EID 7045: Service installed (Sliver psexec)'
|
|
- 'Sysmon EID 1: services.exe → Sliver implant binary'
|
|
- 'Sysmon EID 3: mTLS/WireGuard/HTTPS to C2'
|
|
ChokepointMapping: 'Auth via SMB/WMI → service or process created on target → Sliver implant callback to C2'
|
|
- Name: Havoc
|
|
FirstSeen: '2022'
|
|
Status: Active
|
|
SourceURL: https://github.com/HavocFramework/Havoc
|
|
NotesShort: Modern C2 with strong EDR bypass features; uses same underlying Windows execution primitives
|
|
Notes: Modern open-source C2 framework with strong EDR bypass features and lateral movement capabilities; described as 'entry-level
|
|
C2 for serious criminals'; increasingly observed in intrusions alongside or replacing Impacket; uses the same underlying
|
|
Windows execution primitives (service creation, WMI, WinRM)
|
|
VariantId: havoc
|
|
Command:
|
|
Invocation: "havoc > jump psexec <target>\nhavoc > jump winrm <target>\nhavoc > jump wmi <target>\n# Demon agent: position-independent shellcode\n# Supports sleep obfuscation, indirect syscalls, token manipulation"
|
|
Context: 'Open-source C2 with Demon agent. Supports PSExec, WinRM, WMI lateral movement. Agents use indirect syscalls and sleep obfuscation.'
|
|
Artifacts:
|
|
- 'Security EID 4624: Network logon (Type 3)'
|
|
- 'System EID 7045: Service installed (if psexec jump)'
|
|
- 'Sysmon EID 1: services.exe or wmiprvse.exe → Demon loader'
|
|
- 'Sysmon EID 3: HTTPS callback to Havoc teamserver'
|
|
ChokepointMapping: 'Auth via SMB/WMI/WinRM → service/process on target → Demon agent callback to teamserver'
|
|
Prerequisites:
|
|
- Network access to target on at least one required protocol port (SMB 445, WMI/RPC 135, WinRM 5985/5986)
|
|
- Remote execution surface enabled on target (Server service for SMB, WinRM service, WMI, or Task Scheduler)
|
|
Chokepoints:
|
|
- Stage: Network Authentication
|
|
Input: Attacker has valid admin credentials (password, hash, or ticket)
|
|
Invariant: Valid admin credentials (local or domain) must be obtained before any remote execution attempt
|
|
Observable: 'Windows Security EID 4624 (Logon Type 3, Network) with admin account. EID 4672 (Special Privilege
|
|
Logon). Source IP is typically not a known admin workstation.'
|
|
WhyCantBypass: All remote execution tools require authenticated access. No valid credentials means authentication failure
|
|
at every attempted protocol regardless of which tool is used
|
|
LogSources:
|
|
- Windows Security Event ID 4624 (Network Logon)
|
|
- Windows Security Event ID 4672 (Special Privilege Logon)
|
|
- Windows Security Event ID 4648 (Logon with Explicit Credentials)
|
|
- Windows Security Event ID 4769 (Kerberos Service Ticket Request)
|
|
DetectionTier: Research
|
|
SigmaRef: ''
|
|
- Stage: Remote Process/Service Creation
|
|
Input: Authenticated admin session established on target
|
|
Invariant: 'Tool invokes a Windows execution primitive on the remote host: service creation (SMB), WMI process spawn, scheduled
|
|
task creation, or WinRM command'
|
|
Observable: 'Sysmon EID 1 showing services.exe or wmiprvse.exe spawning cmd.exe/powershell.exe. Windows Security
|
|
EID 7045 (Service Installed) for psexec-style tools. EID 4688 with cross-logon session correlation.'
|
|
WhyCantBypass: A command must run on the target via one of these four primitives. No other execution surface exists over
|
|
these authenticated protocols. Tools must first establish an authenticated session over a protocol port (445, 135, 5985/5986).
|
|
No reachable port means no remote execution regardless of credential validity
|
|
LogSources:
|
|
- Windows Security Event ID 4697 / System 7045 (Service Installed)
|
|
- Windows Security Event ID 5145 (IPC$/svcctl share access)
|
|
- Sysmon Event ID 1 (wmiprvse.exe or services.exe spawning cmd.exe/powershell.exe)
|
|
DetectionTier: Analyst
|
|
SigmaRef: sigma-rules/remote-execution/analyst.yml
|
|
BypassNote: LOTL tools (winrs.exe, wmic /node:, Enter-PSSession, Invoke-Command) produce identical telemetry to Impacket
|
|
but with signed Microsoft binaries. Detection must be purely behavioral with no reliance on tool signatures
|
|
- Stage: Lateral Spread
|
|
Input: Remote command interpreter is running on one or more targets
|
|
Invariant: The same credential and execution primitive sequence repeats across multiple hosts in a short window or follows
|
|
a deliberate pivot path
|
|
Observable: 'Windows Security EID 4624 showing the same account authenticating to multiple hosts within minutes.
|
|
Sysmon EID 3 showing same source IP connecting to multiple RFC1918 destinations on SMB/WinRM ports.'
|
|
WhyCantBypass: Lateral movement by definition requires replication of the credential-plus-primitive pattern on each subsequent
|
|
host. The telemetry is identical on every hop
|
|
LogSources:
|
|
- Windows Security Event ID 4624 (multiple target hosts, short window)
|
|
- Sysmon Event ID 3 (same source IP, multiple RFC1918 destinations)
|
|
DetectionTier: Hunt
|
|
SigmaRef: sigma-rules/remote-execution/hunt.yml
|
|
EvolutionTimeline:
|
|
- Date: 2016-Q1
|
|
Event: CrackMapExec released as multi-protocol framework
|
|
Change: Multi-protocol framework combining SMB, WMI, and WinRM in one tool; detection must cover all protocols.
|
|
DetectionImpact: Detection must cover multiple protocols, not just SMB
|
|
Variants: []
|
|
EventType: event
|
|
- Date: 2019-Q2
|
|
Event: Evil-WinRM released as dedicated WinRM exploitation tool
|
|
Change: Dedicated WinRM exploitation tool released; WinRM authentication spike detection becomes important.
|
|
DetectionImpact: WinRM authentication spike detection becomes important
|
|
Variants: []
|
|
EventType: event
|
|
- Date: 2023-Q3
|
|
Event: NetExec forked from CrackMapExec
|
|
Change: Active CrackMapExec fork adds LDAP and SSH support; no fundamental change to underlying Windows API behavior.
|
|
DetectionImpact: No fundamental change to underlying Windows API behaviors
|
|
Variants: []
|
|
EventType: event
|
|
- Date: 2023-Q4
|
|
Event: CrackMapExec officially archived
|
|
Change: CME archived December 6, 2023; behavioral detection remains valid but CME-specific hash/signature rules stop receiving
|
|
updates.
|
|
DetectionImpact: Behavioral detection remains valid; tool-specific hash/signature-based detection for CME becomes stale
|
|
Variants: []
|
|
EventType: event
|
|
- Date: 2025-01
|
|
Event: Impacket adds rdp_shadow.py (PR#2064)
|
|
Change: Native RDP session hijacking (rdp_shadow.py) added to Impacket suite via PR#2064.
|
|
DetectionImpact: Existing RDP session manipulation detection (Event ID 4624 LogonType 10) applies
|
|
Variants: []
|
|
EventType: event
|
|
Detections:
|
|
- Level: Research
|
|
Description: Identify network logon events followed by service creation or remote process execution
|
|
LogSources:
|
|
- Windows Security Event ID 4624 (Successful Logon)
|
|
- Windows Security Event ID 4688 (Process Creation)
|
|
- Windows System Event ID 7045 (Service Installed)
|
|
Logic: 'Network logon (4624 LogonType 3) by a local Administrators or Domain Admins member, followed within 60 seconds by a service creation (7045) or process creation with an elevated token.'
|
|
ExpectedFPRate: High
|
|
UseCase: Baseline normal admin activity; understand legitimate remote administration patterns
|
|
SigmaRule: sigma-rules/remote-execution/research.yml
|
|
- Level: Hunt
|
|
Description: Network logon with suspicious service creation (random name or unusual path) or WMI parent process
|
|
LogSources:
|
|
- Sysmon Event ID 1 (Process Creation)
|
|
- Windows Security Event ID 4624 (Logon)
|
|
- Windows Security Event ID 4697 (Service Installed)
|
|
- Windows System Event ID 7045 (Service Installed)
|
|
Logic: 'Network logon (4624 LogonType 3) AND one of: service created with a random 8-10 char alphanumeric name or binary path in \Windows\Temp\, \Users\Public\, or \ProgramData\; OR process created with parent wmiprvse.exe or services.exe spawning cmd.exe or powershell.exe from unusual paths.'
|
|
ExpectedFPRate: Medium
|
|
UseCase: Active hunt for lateral movement campaigns; identifies PsExec-style and WMI execution
|
|
SigmaRule: sigma-rules/remote-execution/hunt.yml
|
|
- Level: Analyst
|
|
Description: Network logon + IPC$ access + suspicious service or multiple hosts in spray pattern
|
|
LogSources:
|
|
- Sysmon Event ID 1 (Process Creation)
|
|
- Sysmon Event ID 3 (Network Connection)
|
|
- Windows Security Event ID 4624 (Logon)
|
|
- Windows Security Event ID 4697/7045 (Service)
|
|
- Windows Security Event ID 5145 (Detailed File Share)
|
|
Logic: 'Network logon (4624 LogonType 3) AND IPC$ share access (5145 ShareName=IPC$) AND service creation with a random 8-10 char name or binary in \Windows\Temp\ or \Users\Public\ or command cmd.exe/powershell.exe. Also fires on spray pattern: same source IP hitting 3+ hosts within 10 minutes, RFC1918 to RFC1918.'
|
|
ExpectedFPRate: Low
|
|
UseCase: SOC alerting for active lateral movement; direct IR escalation trigger
|
|
SigmaRule: sigma-rules/remote-execution/analyst.yml
|
|
Intel:
|
|
- Name: MITRE ATT&CK - Impacket Software S0357
|
|
Tier: primary
|
|
URL: https://attack.mitre.org/software/S0357/
|
|
Description: Lists every known threat actor (APT groups, ransomware operators) documented using Impacket; far more useful
|
|
to a defender than the raw GitHub repo for understanding real-world prevalence
|
|
- Name: MITRE ATT&CK - T1021.003 DCOM
|
|
Tier: primary
|
|
URL: https://attack.mitre.org/techniques/T1021/003/
|
|
Description: Technique definition for DCOM-based lateral movement; covers dcomexec.py usage and detection guidance
|
|
- Name: MITRE ATT&CK - T1569.002 Service Execution
|
|
Tier: primary
|
|
URL: https://attack.mitre.org/techniques/T1569/002/
|
|
Description: Technique definition for service-based remote execution (psexec/smbexec pattern); the primary detection signal
|
|
in this chokepoint's hunt and analyst rules
|
|
- Name: Microsoft - Storm-0501 Ransomware Hybrid Cloud Attacks
|
|
Tier: primary
|
|
URL: https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/
|
|
Description: Documents Storm-0501 using Impacket SecretsDump for lateral movement in hybrid cloud environments; concrete
|
|
example of Impacket use in a 2024 ransomware campaign
|
|
LinkedFrom:
|
|
- Impacket
|
|
- Name: Impacket GitHub
|
|
Tier: primary
|
|
URL: https://github.com/fortra/impacket
|
|
Description: Monitor releases and PRs for new execution modules; source of truth for what capabilities the suite currently
|
|
covers
|
|
- Name: NetExec GitHub
|
|
Tier: primary
|
|
URL: https://github.com/Pennyw0rth/NetExec
|
|
Description: Active successor to CrackMapExec; track new protocol support and OPSEC improvements that affect detection
|
|
- Name: SOC Investigation - Event ID 5145 Threat Hunting
|
|
Tier: primary
|
|
URL: https://www.socinvestigation.com/threat-hunting-with-eventid-5145-object-access-detailed-file-share/
|
|
Description: Detailed guidance on using Event ID 5145 (Detailed File Share) for lateral movement detection; covers IPC$
|
|
access correlation
|
|
LinkedFrom:
|
|
- Remote Execution Primitive
|
|
RelatedChokepoints:
|
|
- ransomware-service-manipulation
|
|
OsintSources:
|
|
- Platform: Shodan
|
|
Query: port:5985 product:"Microsoft HTTPAPI"
|
|
URL: https://www.shodan.io/search?query=port%3A5985+product%3A%22Microsoft+HTTPAPI%22
|
|
Notes: Finds internet-exposed WinRM endpoints; narrow with 'org:' or 'net:' filters to audit your own attack surface. Run
|
|
a second query on port 5986 for the HTTPS variant.
|
|
- Platform: Shodan
|
|
Query: ssl.jarm:07d14d16d21d21d00042d41d00041de5fb3038104f457d92ba37e62256d5 port:443
|
|
URL: https://www.shodan.io/search?query=ssl.jarm%3A07d14d16d21d21d00042d41d00041de5fb3038104f457d92ba37e62256d5
|
|
Notes: Clusters of hosts sharing this default Cobalt Strike JARM fingerprint are likely team servers; more resilient to
|
|
infrastructure rotation than IP/domain blocklists.
|
|
- Platform: GitHub Code Search
|
|
Query: '"wmiexec" OR "smbexec" OR "atexec" path:*.py'
|
|
URL: https://github.com/search?q=%22wmiexec%22+OR+%22smbexec%22+OR+%22atexec%22+path%3A*.py&type=code
|
|
Notes: Finds community tools built on Impacket execution primitives; use for defender awareness of new modules extending
|
|
the execution surface.
|
|
KnownBypasses:
|
|
- Bypass: Using legitimate service names that blend in with existing services
|
|
Mitigation: Maintain a baseline of approved services; alert on any new service creation.
|
|
- Bypass: NTLM relay attacks instead of direct credential use
|
|
Mitigation: Enable SMB signing and LDAP signing; disable NTLM where operationally feasible.
|
|
- Bypass: Using legitimate admin tools (psexec.exe from Sysinternals)
|
|
Mitigation: Enforce software allowlisting and monitor hash for known-good vs. impersonated versions.
|
|
- Bypass: Living Off the Land using built-in Windows admin tools (winrs.exe, wmic /node:, Enter-PSSession)
|
|
Mitigation: Restrict WinRM and WMI access via Windows Firewall; require PAW for remote administration.
|
|
- Bypass: Kerberos-based lateral movement (Overpass-the-Hash, Pass-the-Ticket, Silver/Golden Tickets)
|
|
Mitigation: Enable AES encryption for Kerberos; protect the krbtgt account; monitor for anomalous TGS requests.
|
|
YaraRules:
|
|
- yara-rules/impacket-indicators.yar
|
|
RawLogs:
|
|
- Type: Windows Event Log
|
|
EventId: 4624
|
|
Source: Microsoft-Windows-Security-Auditing
|
|
Description: Network logon (Type 3) from attacker IP before remote execution
|
|
MatchedRules:
|
|
- Research
|
|
- Analyst
|
|
Sample: 'EventID: 4624 (An account was successfully logged on)
|
|
|
|
TimeCreated: 2024-07-09T01:33:47.2284110Z
|
|
|
|
Channel: Security
|
|
|
|
|
|
LogonType: 3
|
|
|
|
NewLogonUserName: Administrator
|
|
|
|
NewLogonDomain: CORP
|
|
|
|
AuthenticationPackageName: NTLM
|
|
|
|
LogonProcessName: NtLmSsp
|
|
|
|
IpAddress: 10.10.50.5
|
|
|
|
IpPort: 49221
|
|
|
|
# LogonType=3 (Network) from internal IP. Pre-execution authentication.
|
|
|
|
'
|
|
- Type: Windows Event Log
|
|
EventId: 5145
|
|
Source: Microsoft-Windows-Security-Auditing
|
|
Description: IPC$ share access. PsExec/Impacket opens IPC$/svcctl before service creation
|
|
MatchedRules:
|
|
- Analyst
|
|
Sample: 'EventID: 5145 (A network share object was checked for access)
|
|
|
|
TimeCreated: 2024-07-09T01:33:47.4418230Z
|
|
|
|
Channel: Security
|
|
|
|
|
|
SubjectUserName: Administrator
|
|
|
|
ShareName: \\*\IPC$
|
|
|
|
RelativeTargetName: svcctl
|
|
|
|
AccessList: %%4416 (ReadData)
|
|
|
|
IpAddress: 10.10.50.5
|
|
|
|
# IPC$/svcctl access = opening service control manager over SMB (PsExec/Impacket pattern)
|
|
|
|
'
|
|
- Type: Windows Event Log
|
|
EventId: 7045
|
|
Source: Service Control Manager
|
|
Description: Random-named service installed from TEMP path. Classic PsExec/Impacket signature
|
|
MatchedRules:
|
|
- Research
|
|
- Hunt
|
|
- Analyst
|
|
Sample: 'EventID: 7045 (A new service was installed in the system)
|
|
|
|
TimeCreated: 2024-07-09T01:33:47.8834120Z
|
|
|
|
Channel: System
|
|
|
|
|
|
ServiceName: xvkbmrfe
|
|
|
|
ServiceFileName: C:\Windows\Temp\xvkbmrfe.exe
|
|
|
|
ServiceType: user mode service
|
|
|
|
ServiceStartType: demand start
|
|
|
|
ServiceAccount: LocalSystem
|
|
|
|
# 8-char random name + TEMP binary path = PsExec/Impacket/CrackMapExec pattern
|
|
|
|
'
|
|
- Type: Sysmon
|
|
EventId: 1
|
|
Source: Microsoft-Windows-Sysmon/Operational
|
|
Description: cmd.exe spawned from services.exe. Service binary executing attacker commands
|
|
MatchedRules:
|
|
- Hunt
|
|
- Analyst
|
|
Sample: 'EventID: 1 (Process Create)
|
|
|
|
UtcTime: 2024-07-09 01:33:48.227
|
|
|
|
ProcessId: 4096
|
|
|
|
Image: C:\Windows\System32\cmd.exe
|
|
|
|
CommandLine: cmd.exe /Q /c whoami 1>\\127.0.0.1\ADMIN$\__1720488827.18 2>&1
|
|
|
|
ParentProcessId: 612
|
|
|
|
ParentImage: C:\Windows\System32\services.exe
|
|
|
|
# services.exe → cmd.exe is the canonical PsExec parent chain
|
|
|
|
# Output redirected to ADMIN$ share. PsExec output capture pattern.
|
|
|
|
'
|
|
EmulationScript:
|
|
File: emulation/remote-execution-tools/emulate.ps1
|
|
Language: powershell
|
|
Description: Simulates network logon, IPC$ access, random-named service creation, and cmd.exe execution
|
|
SafetyNotes: Requires Administrator. All activity targets localhost only. Run in isolated lab VM.
|
|
AtomicRef: T1021.002
|
|
TheConstant: Valid admin credentials → authenticated protocol (SMB/WMI/WinRM) → remote command execution
|
|
PreventionSummary: >
|
|
Valid credentials alone are not sufficient if the offensive tools that use them are blocked.
|
|
Restricting dual-use admin utilities (PsExec, Impacket, NetExec) from executing on endpoints
|
|
prevents lateral movement even when an attacker has valid admin credentials.
|
|
PreventionOpportunities:
|
|
- Category: Endpoint · Application Control
|
|
Control: Block dual-use offensive tools from executing on workstations and servers
|
|
Impact: Prevents lateral movement even when the attacker holds valid admin credentials - the
|
|
tools themselves become the chokepoint that is blocked.
|
|
MagicSwordFit: MagicSword's LOLBAS / dual-use controls block offensive admin tools
|
|
(Impacket, NetExec, PsExec, CrackMapExec) by default, with policy tuned to allow only
|
|
what your teams legitimately need.
|
|
MagicSwordTag: lolbas
|
|
- Category: Identity
|
|
Control: Enforce tiered admin accounts with MFA and eliminate standing admin access
|
|
Impact: Valid credentials are harder to obtain and reuse across the network; removes the
|
|
"credentials = immediate access" assumption.
|
|
- Category: Network
|
|
Control: Segment workstation-to-workstation SMB (445/TCP) and WMI (135/TCP) traffic
|
|
Impact: Blocks the lateral movement protocols at the network layer even if tools execute,
|
|
limiting the blast radius of any single compromised host.
|