{"id":"1ce8c8a3-2723-48ed-8246-906ac91061a6","title":"Possible PetitPotam Coerce Authentication Attempt","description":"Detect PetitPotam coerced authentication activity.","author":"Mauricio Velazco, Michael Haag","status":"test","level":"high","date":"2021-09-02","modified":"2022-08-11","tags":["attack.credential-access","attack.t1187"],"technique_ids":["T1187"],"logsource":{"product":"windows","service":"security","definition":"The advanced audit policy setting \"Object Access > Detailed File Share\" must be configured for Success/Failure"},"falsepositives":["Unknown. Feedback welcomed."],"references":["https://github.com/topotam/PetitPotam","https://github.com/splunk/security_content/blob/0dd6de32de2118b2818550df9e65255f4109a56d/detections/endpoint/petitpotam_network_share_access_request.yml"],"source_path":"rules/windows/builtin/security/win_security_petitpotam_network_share.yml","source_sha256":"a2865278a9362df76046133b4cabba3f85e2046f1e2105bb94eed8b3bf825db3","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/security/win_security_petitpotam_network_share.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Possible PetitPotam Coerce Authentication Attempt\nid: 1ce8c8a3-2723-48ed-8246-906ac91061a6\nstatus: test\ndescription: Detect PetitPotam coerced authentication activity.\nreferences:\n    - https://github.com/topotam/PetitPotam\n    - https://github.com/splunk/security_content/blob/0dd6de32de2118b2818550df9e65255f4109a56d/detections/endpoint/petitpotam_network_share_access_request.yml\nauthor: Mauricio Velazco, Michael Haag\ndate: 2021-09-02\nmodified: 2022-08-11\ntags:\n    - attack.credential-access\n    - attack.t1187\nlogsource:\n    product: windows\n    service: security\n    definition: 'The advanced audit policy setting \"Object Access > Detailed File Share\" must be configured for Success/Failure'\ndetection:\n    selection:\n        EventID: 5145\n        ShareName|startswith: '\\\\\\\\' # looking for the string \\\\somethink\\IPC$\n        ShareName|endswith: '\\IPC$'\n        RelativeTargetName: lsarpc\n        SubjectUserName: ANONYMOUS LOGON\n    condition: selection\nfalsepositives:\n    - Unknown. Feedback welcomed.\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1187","id":"T1187","name":"Forced Authentication","page":"techniques/enterprise/T1187/"}],"data_path":"data/detection-rules/1ce8c8a3-2723-48ed-8246-906ac91061a6.json","kind":"sigma"}
