{"id":"18f37338-b9bd-4117-a039-280c81f7a596","title":"Zerologon Exploitation Using Well-known Tools","description":"This rule is designed to detect attempts to exploit Zerologon (CVE-2020-1472) vulnerability using mimikatz zerologon module or other exploits from machine with \"kali\" hostname.","author":"Demyan Sokolin @_drd0c, Teymur Kheirkhabarov @HeirhabarovT, oscd.community","status":"stable","level":"critical","date":"2020-10-13","modified":"2021-05-30","tags":["attack.t1210","attack.lateral-movement"],"technique_ids":["T1210"],"logsource":{"service":"system","product":"windows"},"falsepositives":[],"references":["https://www.secura.com/blog/zero-logon","https://bi-zone.medium.com/hunting-for-zerologon-f65c61586382"],"source_path":"rules/windows/builtin/system/netlogon/win_system_possible_zerologon_exploitation_using_wellknown_tools.yml","source_sha256":"01280cfdc62932dbfb15688746e728686ed578ffbd98606a7d6ecf2c03c9649e","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/system/netlogon/win_system_possible_zerologon_exploitation_using_wellknown_tools.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Zerologon Exploitation Using Well-known Tools\nid: 18f37338-b9bd-4117-a039-280c81f7a596\nstatus: stable\ndescription: This rule is designed to detect attempts to exploit Zerologon (CVE-2020-1472) vulnerability using mimikatz zerologon module or other exploits from machine with \"kali\" hostname.\nreferences:\n    - https://www.secura.com/blog/zero-logon\n    - https://bi-zone.medium.com/hunting-for-zerologon-f65c61586382\nauthor: 'Demyan Sokolin @_drd0c, Teymur Kheirkhabarov @HeirhabarovT, oscd.community'\ndate: 2020-10-13\nmodified: 2021-05-30\ntags:\n    - attack.t1210\n    - attack.lateral-movement\nlogsource:\n    service: system\n    product: windows\ndetection:\n    selection:\n        EventID:\n            - 5805\n            - 5723\n    keywords:\n        - kali\n        - mimikatz\n    condition: selection and keywords\nlevel: critical\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1210","id":"T1210","name":"Exploitation of Remote Services","page":"techniques/enterprise/T1210/"}],"data_path":"data/detection-rules/18f37338-b9bd-4117-a039-280c81f7a596.json","kind":"sigma"}
