Vendor: Linux

July 25, 2023 · View on GitHub

Product: SSH

Use-Case: Lateral Movement

RulesModelsMITRE TTPsEvent TypesParsers
167611
Event TypeRulesModels
remote-logonT1550.002 - Use Alternate Authentication Material: Pass the Hash
A-NTLM-WsSrv: Hostname contains workstation or server
A-PTH-ALERT-sH-Possible: Possible pass the hash attack with keylength of 0 in NTLM event and a 'null' sid on this source host.
AE-NTLM-WsSrv: New generic hostname found using ntlm authentication
NTLM-mismatch:
PTH-ALERT-sH-Possible: Possible pass the hash attack with keylength of 0 in NTLM event and a 'null' sid.

T1550 - Use Alternate Authentication Material
RLA-UAPackage-F: First time usage of Windows authentication package
RLA-UAPackage-A: Abnormal usage of Windows authentication package

T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
A-KL-ToEt-Roast: Suspicious or weak encryption type used for obtaining the kerberos TGTs using non kerberos service for this asset
KL-ToEt-Roast: Suspicious or weak encryption type used for obtaining kerberos TGTs using non kerberos service

T1558 - Steal or Forge Kerberos Tickets
EXPERT-PENTEST-DOMAINS: Possible credentials theft attack detected

T1021 - Remote Services
A-RLA-sHdZ-F: First remote access to zone from asset
A-RLA-sHdZ-A: Abnormal remote access to zone from asset
A-RLA-dHsZ-F: First remote access from zone to asset
A-RLA-dHsZ-A: Abnormal remote access from zone to asset
RLA-UsH-dZ-F: First remote access to zone from new asset
RLA-UsH-dZ-A: Abnormal remote access to zone from new asset

T1078 - Valid Accounts
RLA-UsH-dZ-F: First remote access to zone from new asset
RLA-UsH-dZ-A: Abnormal remote access to zone from new asset
RLA-UAPackage: Windows authentication packages used when connecting to remote hosts
AE-NTLM: Models ntlm hostnames in the organization
AE-OHr: Random hostnames
AL-UsH: Source hosts per User
A-AE-OHr: Random hostnames on asset
A-RLA-dHsZ: Destination Host to Source zone communication
A-RLA-sHdZ: Source Host to Destination zone communication