{"id":"24549159-ac1b-479c-8175-d42aea947cae","title":"Hacktool Ruler","description":"This events that are generated when using the hacktool Ruler by Sensepost","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-05-31","modified":"2022-10-09","tags":["attack.discovery","attack.execution","attack.collection","attack.lateral-movement","attack.t1087","attack.t1114","attack.t1059","attack.t1550.002"],"technique_ids":["T1059","T1087","T1114","T1550.002"],"logsource":{"product":"windows","service":"security"},"falsepositives":["Go utilities that use staaldraad awesome NTLM library"],"references":["https://github.com/sensepost/ruler","https://github.com/sensepost/ruler/issues/47","https://github.com/staaldraad/go-ntlm/blob/cd032d41aa8ce5751c07cb7945400c0f5c81e2eb/ntlm/ntlmv1.go#L427","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4776","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4624"],"source_path":"rules/windows/builtin/security/win_security_alert_ruler.yml","source_sha256":"2774e1d5a0c418a3eceab1de94107ef740df79b212a0ca37159bacb22ca0fdbd","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/security/win_security_alert_ruler.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Hacktool Ruler\nid: 24549159-ac1b-479c-8175-d42aea947cae\nstatus: test\ndescription: This events that are generated when using the hacktool Ruler by Sensepost\nreferences:\n    - https://github.com/sensepost/ruler\n    - https://github.com/sensepost/ruler/issues/47\n    - https://github.com/staaldraad/go-ntlm/blob/cd032d41aa8ce5751c07cb7945400c0f5c81e2eb/ntlm/ntlmv1.go#L427\n    - https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4776\n    - https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4624\nauthor: Florian Roth (Nextron Systems)\ndate: 2017-05-31\nmodified: 2022-10-09\ntags:\n    - attack.discovery\n    - attack.execution\n    - attack.collection\n    - attack.lateral-movement\n    - attack.t1087\n    - attack.t1114\n    - attack.t1059\n    - attack.t1550.002\nlogsource:\n    product: windows\n    service: security\ndetection:\n    selection1:\n        EventID: 4776\n        Workstation: 'RULER'\n    selection2:\n        EventID:\n            - 4624\n            - 4625\n        WorkstationName: 'RULER'\n    condition: (1 of selection*)\nfalsepositives:\n    - Go utilities that use staaldraad awesome NTLM library\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1059","id":"T1059","name":"Command and Scripting Interpreter","page":"techniques/enterprise/T1059/"},{"key":"enterprise/T1087","id":"T1087","name":"Account Discovery","page":"techniques/enterprise/T1087/"},{"key":"enterprise/T1114","id":"T1114","name":"Email Collection","page":"techniques/enterprise/T1114/"},{"key":"enterprise/T1550.002","id":"T1550.002","name":"Pass the Hash","page":"techniques/enterprise/T1550.002/"}],"data_path":"data/detection-rules/24549159-ac1b-479c-8175-d42aea947cae.json","kind":"sigma"}
