mirror of
https://github.com/iimp0ster/detection-chokepoints
synced 2026-08-09 12:41:00 +00:00
Adds RawLogs and EmulationScript fields to all 6 remaining chokepoints and creates PowerShell emulation scripts that generate real Sysmon/WEL telemetry for detection validation without requiring live malware. Chokepoints covered: - clickfix-techniques: 3 log samples (Sysmon EID 1/3/22), VBScript→PowerShell shim - renamed-rmm-tools: 3 log samples (Sysmon EID 11/1/3), binary rename + metadata mismatch - edr-bypass-techniques: 4 log samples (Sysmon EID 6/10, WEL 7036/7040), process handle + service stop - ransomware-service-manipulation: 5 log samples (Sysmon EID 1, WEL 7036/7040), bulk service kill pattern - remote-execution-tools: 4 log samples (WEL 4624/5145/7045, Sysmon EID 1), IPC$+random service pattern - web-shells: 4 log samples (Sysmon EID 11/1/3), w3wp.exe→cmd.exe parent chain Each emulation script: - Generates authentic Sysmon/WEL telemetry matching Research/Hunt/Analyst rule logic - Documents exactly which sigma rule tier each step triggers - Is safe for isolated lab use (no real malware, no credentials exfiltrated) - Includes cleanup, verbose mode, and selective skip flags Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
304 lines
17 KiB
YAML
304 lines
17 KiB
YAML
---
|
|
Name: Remote Execution Tools (HackTools)
|
|
Id: d4e6f8a0-2b3c-5d7e-9f1a-4c6b8d0e2f4a
|
|
MitreIds:
|
|
- T1021.002
|
|
- T1021.003
|
|
- T1021.006
|
|
- T1047
|
|
- T1053.005
|
|
- T1569.002
|
|
Tactics:
|
|
- Lateral Movement
|
|
- Execution
|
|
Techniques:
|
|
- "Remote Services: SMB/Windows Admin Shares"
|
|
- "Remote Services: Distributed Component Object Model"
|
|
- "Remote Services: Windows Remote Management"
|
|
- "Windows Management Instrumentation"
|
|
- "Scheduled Task/Job: Scheduled Task"
|
|
- "System Services: Service Execution"
|
|
DetectionPriority: HIGH
|
|
ThreatPrevalence: HIGH
|
|
DetectionDifficulty: MEDIUM
|
|
Description: >
|
|
Offensive security tools (Impacket, NetExec, CrackMapExec, Evil-WinRM) used for
|
|
remote code execution across Windows environments. These frameworks wrap legitimate
|
|
Windows protocols (SMB, WMI, WinRM, RPC) to execute code on remote systems using
|
|
valid admin credentials. Despite tool diversity, the chokepoint is invariant: valid
|
|
admin credentials, network access to target ports, and a remote execution primitive
|
|
(service creation, WMI process, scheduled task) are always required.
|
|
LastUpdated: "2026-03-07"
|
|
Author: "@iimp0ster"
|
|
|
|
Variations:
|
|
- Name: Impacket
|
|
FirstSeen: "2015"
|
|
Status: Active
|
|
Notes: >
|
|
Python suite with multiple execution modules:
|
|
psexec.py (SMB service creation), smbexec.py (SMB + scheduled tasks),
|
|
wmiexec.py (WMI process creation), atexec.py (Task Scheduler),
|
|
dcomexec.py (DCOM), rdp_shadow.py (RDP session hijacking, added 2025-01)
|
|
- Name: CrackMapExec
|
|
FirstSeen: "2016"
|
|
Status: Archived
|
|
Notes: "Multi-protocol framework covering SMB, WMI, WinRM, MSSQL; original repository archived by maintainer on December 6, 2023 (read-only); superseded by NetExec — defenders should not expect CME-specific signatures to receive community updates"
|
|
- Name: NetExec
|
|
FirstSeen: "2023"
|
|
Status: Active
|
|
Notes: Active CrackMapExec fork; adds LDAP, SSH, improved OPSEC features
|
|
- Name: Evil-WinRM
|
|
FirstSeen: "2019"
|
|
Status: Active
|
|
Notes: Dedicated WinRM exploitation tool; targets port 5985/5986
|
|
- Name: Metasploit psexec
|
|
FirstSeen: "2007"
|
|
Status: Active
|
|
Notes: Original PsExec-style SMB execution via Metasploit framework
|
|
- Name: Sliver
|
|
FirstSeen: "2020"
|
|
Status: Active
|
|
Notes: "Open-source C2 framework widely adopted by nation-state and ransomware actors as a Cobalt Strike alternative; built-in lateral movement over SMB/WMI using the same execution primitives this chokepoint detects; used by threat actors following Fortra's crackdown on pirated Cobalt Strike licenses"
|
|
- Name: Havoc
|
|
FirstSeen: "2022"
|
|
Status: Active
|
|
Notes: "Modern open-source C2 framework with strong EDR bypass features and lateral movement capabilities; described as 'entry-level C2 for serious criminals'; increasingly observed in intrusions alongside or replacing Impacket; uses the same underlying Windows execution primitives (service creation, WMI, WinRM)"
|
|
|
|
Prerequisites:
|
|
- Valid admin credentials for target system (local or domain)
|
|
- Network access to target on required protocol ports (SMB 445, WMI 135, WinRM 5985/5986, RPC 135/139)
|
|
- Remote execution capability on target (service creation, WMI, scheduled task, WinRM endpoint enabled)
|
|
- Target services must be running (Server service for SMB, WinRM service, etc.)
|
|
|
|
EvolutionTimeline:
|
|
- Date: "2016-Q1"
|
|
Event: CrackMapExec released as multi-protocol framework
|
|
Change: Combined reconnaissance and lateral movement in one tool; SMB, WMI, WinRM in single interface
|
|
DetectionImpact: Detection must cover multiple protocols, not just SMB
|
|
TheConstant: "Admin creds + network access + remote execution primitive"
|
|
- Date: "2019-Q2"
|
|
Event: Evil-WinRM released as dedicated WinRM exploitation tool
|
|
Change: Simplified WinRM-specific lateral movement; requires WinRM enabled on target
|
|
DetectionImpact: WinRM authentication spike detection becomes important
|
|
TheConstant: "Admin creds + network access + remote execution primitive"
|
|
- Date: "2023-Q3"
|
|
Event: NetExec forked from CrackMapExec
|
|
Change: Active development, LDAP/SSH support, improved operational security features
|
|
DetectionImpact: No fundamental change to underlying Windows API behaviors
|
|
TheConstant: "Admin creds + network access + remote execution primitive"
|
|
- Date: "2023-Q4"
|
|
Event: CrackMapExec officially archived
|
|
Change: Original CME repository archived December 6, 2023; NetExec becomes the de facto community standard; CME-specific binary signatures and detection rules stop receiving community updates
|
|
DetectionImpact: Behavioral detection remains valid; tool-specific hash/signature-based detection for CME becomes stale
|
|
TheConstant: "Admin creds + network access + remote execution primitive"
|
|
- Date: "2025-01"
|
|
Event: Impacket adds rdp_shadow.py (PR#2064)
|
|
Change: Native RDP session hijacking capability added to Impacket suite
|
|
DetectionImpact: Existing RDP session manipulation detection (Event ID 4624 LogonType 10) applies
|
|
TheConstant: "Admin creds + network access + remote execution primitive"
|
|
|
|
Detections:
|
|
- Level: Research
|
|
Description: Identify network logon events followed by service creation or remote process execution
|
|
LogSources:
|
|
- "Windows Security Event ID 4624 (Successful Logon)"
|
|
- "Windows Security Event ID 4688 (Process Creation)"
|
|
- "Windows System Event ID 7045 (Service Installed)"
|
|
Logic: >
|
|
Event ID: 4624
|
|
LogonType: 3 (Network)
|
|
Account: Member of local Administrators or Domain Admins
|
|
Within 60 seconds: Service creation (7045) OR process creation with elevated token
|
|
ExpectedFPRate: High
|
|
UseCase: Baseline normal admin activity; understand legitimate remote administration patterns
|
|
SigmaRule: sigma-rules/remote-execution/research.yml
|
|
|
|
- Level: Hunt
|
|
Description: Network logon with suspicious service creation (random name or unusual path) or WMI parent process
|
|
LogSources:
|
|
- "Sysmon Event ID 1 (Process Creation)"
|
|
- "Windows Security Event ID 4624 (Logon)"
|
|
- "Windows Security Event ID 4697 (Service Installed)"
|
|
- "Windows System Event ID 7045 (Service Installed)"
|
|
Logic: >
|
|
Network Logon (4624, LogonType 3)
|
|
AND one of:
|
|
Service Created with:
|
|
- Name: matches random pattern (8-10 char alpha-numeric)
|
|
- Binary Path: \Windows\Temp\ OR \Users\Public\ OR \ProgramData\
|
|
OR Process Created with:
|
|
- Parent: wmiprvse.exe OR services.exe
|
|
- Image: cmd.exe OR powershell.exe
|
|
- Path: unusual system paths
|
|
ExpectedFPRate: Medium
|
|
UseCase: Active hunt for lateral movement campaigns; identifies PsExec-style and WMI execution
|
|
SigmaRule: sigma-rules/remote-execution/hunt.yml
|
|
|
|
- Level: Analyst
|
|
Description: Network logon + IPC$ access + suspicious service or multiple hosts in spray pattern
|
|
LogSources:
|
|
- "Sysmon Event ID 1 (Process Creation)"
|
|
- "Sysmon Event ID 3 (Network Connection)"
|
|
- "Windows Security Event ID 4624 (Logon)"
|
|
- "Windows Security Event ID 4697/7045 (Service)"
|
|
- "Windows Security Event ID 5145 (Detailed File Share)"
|
|
Logic: >
|
|
Network Logon (4624, LogonType 3)
|
|
+ IPC$ share access (5145, ShareName = IPC$)
|
|
+ Service creation with suspicious characteristics:
|
|
Name: 8-10 random alphanumeric characters
|
|
Binary: runs from \Windows\Temp\ OR \Users\Public\ OR command is cmd.exe/powershell.exe
|
|
OR + Pattern: same source IP accessing 3+ hosts within 10 minutes (spray)
|
|
Source IP: internal lateral movement (RFC1918 source to RFC1918 destination)
|
|
ExpectedFPRate: Low
|
|
UseCase: SOC alerting for active lateral movement; direct IR escalation trigger
|
|
SigmaRule: sigma-rules/remote-execution/analyst.yml
|
|
|
|
Intel:
|
|
- Name: MITRE ATT&CK — Impacket Software S0357
|
|
URL: https://attack.mitre.org/software/S0357/
|
|
Description: Lists every known threat actor (APT groups, ransomware operators) documented using Impacket; far more useful to a defender than the raw GitHub repo for understanding real-world prevalence
|
|
- Name: MITRE ATT&CK — T1021.003 DCOM
|
|
URL: https://attack.mitre.org/techniques/T1021/003/
|
|
Description: Technique definition for DCOM-based lateral movement; covers dcomexec.py usage and detection guidance
|
|
- Name: MITRE ATT&CK — T1569.002 Service Execution
|
|
URL: https://attack.mitre.org/techniques/T1569/002/
|
|
Description: Technique definition for service-based remote execution (psexec/smbexec pattern); the primary detection signal in this chokepoint's hunt and analyst rules
|
|
- Name: Microsoft — Storm-0501 Ransomware Hybrid Cloud Attacks
|
|
URL: https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/
|
|
Description: Documents Storm-0501 using Impacket SecretsDump for lateral movement in hybrid cloud environments; concrete example of Impacket use in a 2024 ransomware campaign
|
|
- Name: ThreatLocker — Top 10 Post-Exploitation Tools Threat Actors Use
|
|
URL: https://www.threatlocker.com/blog/top-post-exploitation-tools-threat-actors-use
|
|
Description: Real-world prevalence data for post-exploitation tooling including Impacket, NetExec, and C2 frameworks observed across actual intrusions
|
|
- Name: Impacket GitHub
|
|
URL: https://github.com/fortra/impacket
|
|
Description: Monitor releases and PRs for new execution modules; source of truth for what capabilities the suite currently covers
|
|
- Name: NetExec GitHub
|
|
URL: https://github.com/Pennyw0rth/NetExec
|
|
Description: Active successor to CrackMapExec; track new protocol support and OPSEC improvements that affect detection
|
|
- Name: SOC Investigation — Event ID 5145 Threat Hunting
|
|
URL: https://www.socinvestigation.com/threat-hunting-with-eventid-5145-object-access-detailed-file-share/
|
|
Description: Detailed guidance on using Event ID 5145 (Detailed File Share) for lateral movement detection; covers IPC$ access correlation
|
|
|
|
RelatedChokepoints:
|
|
- ransomware-service-manipulation
|
|
|
|
OsintSources:
|
|
- Platform: Shodan
|
|
Query: 'port:5985 product:"Microsoft HTTPAPI"'
|
|
URL: "https://www.shodan.io/search?query=port%3A5985+product%3A%22Microsoft+HTTPAPI%22"
|
|
Notes: "Finds internet-exposed WinRM endpoints (Evil-WinRM targets). Use as an exposure audit to identify unintentionally exposed WinRM in your own IP ranges (narrow with 'org:' or 'net:' filters). Port 5986 is the HTTPS variant — run a second query substituting 5986. Note: searching for exposed ports finds your attack surface, not attacker infrastructure — for hunting attacker C2, use the JARM query below."
|
|
- Platform: Shodan
|
|
Query: 'ssl.jarm:07d14d16d21d21d00042d41d00041de5fb3038104f457d92ba37e62256d5 port:443'
|
|
URL: "https://www.shodan.io/search?query=ssl.jarm%3A07d14d16d21d21d00042d41d00041de5fb3038104f457d92ba37e62256d5"
|
|
Notes: "Default Cobalt Strike JARM fingerprint. Clusters of hosts sharing this fingerprint are likely Cobalt Strike team servers — the most common C2 framework used alongside Impacket/NetExec in lateral movement chains. JARM fingerprints are more resilient to infrastructure rotation than IP/domain blocklists. Also search for Sliver C2 (ssl.jarm:29d29d00029d29d00042d41d00041d2aa5ce6a70de7ba95aef77a77b00a0af) and check hunt.io for current Havoc signatures."
|
|
- Platform: GitHub Code Search
|
|
Query: '"wmiexec" OR "smbexec" OR "atexec" path:*.py'
|
|
URL: "https://github.com/search?q=%22wmiexec%22+OR+%22smbexec%22+OR+%22atexec%22+path%3A*.py&type=code"
|
|
Notes: "Finds community tools and forks built on Impacket execution primitives. Monitor for new modules that extend the execution surface beyond the known chokepoint. This is a tool-tracking query (defender awareness), not infrastructure hunting — results are researcher repos, not attacker infrastructure."
|
|
- Platform: hunt.io
|
|
URL: "https://hunt.io"
|
|
Notes: "Specialized threat hunting platform that maps active C2 infrastructure in real time. Use to search for Cobalt Strike, Sliver, Havoc, and Metasploit infrastructure — the C2 frameworks most commonly paired with Impacket/NetExec lateral movement. The AttackCapture feed tags servers by framework based on banner, certificate, and behavioral fingerprints."
|
|
|
|
KnownBypasses:
|
|
- Bypass: Using legitimate service names that blend in with existing services
|
|
Mitigation: Maintain baseline of approved services; alert on new service creation
|
|
Detection: Correlate service creation with the binary path and network logon context
|
|
- Bypass: Delayed execution after service creation
|
|
Mitigation: N/A
|
|
Detection: Extend correlation window; focus on IPC$ + service creation regardless of timing
|
|
- Bypass: NTLM relay attacks instead of direct credential use
|
|
Mitigation: Enable SMB signing and LDAP signing; disable NTLM where possible
|
|
Detection: Detect relay patterns (source relays to destination within seconds of receiving auth)
|
|
- Bypass: Using legitimate admin tools (psexec.exe from Sysinternals)
|
|
Mitigation: Software allowlisting; monitor hash for known-good vs. impersonated versions
|
|
Detection: Same IPC$ + service creation pattern applies; tool-agnostic detection covers this
|
|
- Bypass: Living Off the Land (LOTL) — built-in Windows admin tools (winrs.exe, wmic /node:, Enter-PSSession, Invoke-Command)
|
|
Mitigation: Restrict WinRM and WMI access via Windows Firewall; require PAW (Privileged Access Workstation) for remote admin; log and alert on PowerShell remoting to non-standard targets
|
|
Detection: "These tools produce identical event telemetry to Impacket/NetExec (4624 LogonType 3, 4688 wmiprvse.exe child, 7045 service install) but with signed Microsoft binaries — no tool signature to match. Detection must be purely behavioral: network logon + protocol + execution primitive, regardless of which binary produced it. A 2024 analysis found 84% of high-severity attacks now use LOTL techniques."
|
|
- Bypass: Kerberos-based lateral movement (Overpass-the-Hash, Pass-the-Ticket, Silver/Golden Tickets)
|
|
Mitigation: Enable AES encryption for Kerberos; protect krbtgt account; monitor for anomalous TGS requests
|
|
Detection: "Bypasses NTLM-relay mitigations and NTLM-focused detection entirely. Detect via Kerberos anomalies: Event ID 4769 (TGS request) with RC4 encryption when AES is expected; Event ID 4768 (TGT request) from non-DC hosts; unusual ticket lifetime or service name patterns. Impacket's getST.py and Rubeus are common tools for ticket forging."
|
|
|
|
YaraRules:
|
|
- yara-rules/impacket-indicators.yar
|
|
|
|
RawLogs:
|
|
- Type: Windows Event Log
|
|
EventId: 4624
|
|
Source: Microsoft-Windows-Security-Auditing
|
|
Description: Network logon (Type 3) from attacker IP before remote execution
|
|
MatchedRules: [Research, Analyst]
|
|
Sample: |
|
|
EventID: 4624 (An account was successfully logged on)
|
|
TimeCreated: 2024-07-09T01:33:47.2284110Z
|
|
Channel: Security
|
|
|
|
LogonType: 3
|
|
NewLogonUserName: Administrator
|
|
NewLogonDomain: CORP
|
|
AuthenticationPackageName: NTLM
|
|
LogonProcessName: NtLmSsp
|
|
IpAddress: 10.10.50.5
|
|
IpPort: 49221
|
|
# LogonType=3 (Network) from internal IP — pre-execution authentication
|
|
|
|
- Type: Windows Event Log
|
|
EventId: 5145
|
|
Source: Microsoft-Windows-Security-Auditing
|
|
Description: IPC$ share access — PsExec/Impacket opens IPC$/svcctl before service creation
|
|
MatchedRules: [Analyst]
|
|
Sample: |
|
|
EventID: 5145 (A network share object was checked for access)
|
|
TimeCreated: 2024-07-09T01:33:47.4418230Z
|
|
Channel: Security
|
|
|
|
SubjectUserName: Administrator
|
|
ShareName: \\*\IPC$
|
|
RelativeTargetName: svcctl
|
|
AccessList: %%4416 (ReadData)
|
|
IpAddress: 10.10.50.5
|
|
# IPC$/svcctl access = opening service control manager over SMB (PsExec/Impacket pattern)
|
|
|
|
- Type: Windows Event Log
|
|
EventId: 7045
|
|
Source: Service Control Manager
|
|
Description: Random-named service installed from TEMP path — classic PsExec/Impacket signature
|
|
MatchedRules: [Research, Hunt, Analyst]
|
|
Sample: |
|
|
EventID: 7045 (A new service was installed in the system)
|
|
TimeCreated: 2024-07-09T01:33:47.8834120Z
|
|
Channel: System
|
|
|
|
ServiceName: xvkbmrfe
|
|
ServiceFileName: C:\Windows\Temp\xvkbmrfe.exe
|
|
ServiceType: user mode service
|
|
ServiceStartType: demand start
|
|
ServiceAccount: LocalSystem
|
|
# 8-char random name + TEMP binary path = PsExec/Impacket/CrackMapExec pattern
|
|
|
|
- Type: Sysmon
|
|
EventId: 1
|
|
Source: Microsoft-Windows-Sysmon/Operational
|
|
Description: cmd.exe spawned from services.exe — service binary executing attacker commands
|
|
MatchedRules: [Hunt, Analyst]
|
|
Sample: |
|
|
EventID: 1 (Process Create)
|
|
UtcTime: 2024-07-09 01:33:48.227
|
|
ProcessId: 4096
|
|
Image: C:\Windows\System32\cmd.exe
|
|
CommandLine: cmd.exe /Q /c whoami 1>\\127.0.0.1\ADMIN$\__1720488827.18 2>&1
|
|
ParentProcessId: 612
|
|
ParentImage: C:\Windows\System32\services.exe
|
|
# services.exe → cmd.exe is the canonical PsExec parent chain
|
|
# Output redirected to ADMIN$ share — PsExec output capture pattern
|
|
|
|
EmulationScript:
|
|
File: emulation/remote-execution-tools/emulate.ps1
|
|
Language: powershell
|
|
Description: Simulates network logon, IPC$ access, random-named service creation, and cmd.exe execution
|
|
SafetyNotes: Requires Administrator. All activity targets localhost only. Run in isolated lab VM.
|
|
AtomicRef: T1021.002
|
|
|