{"id":"3ec9a16d-0b4f-4967-9542-ebf38ceac7dd","title":"OpenCanary - MSSQL Login Attempt Via SQLAuth","description":"Detects instances where an MSSQL service on an OpenCanary node has had a login attempt using SQLAuth.\n","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":"","tags":["attack.credential-access","attack.collection","attack.t1003","attack.t1213"],"technique_ids":["T1003","T1213"],"logsource":{"category":"application","product":"opencanary"},"falsepositives":["Unlikely"],"references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"source_path":"rules/application/opencanary/opencanary_mssql_login_sqlauth.yml","source_sha256":"c7a487c13249524c003f39e2a17c739f22cae2c2983c441835ae7e1457b23365","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/application/opencanary/opencanary_mssql_login_sqlauth.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: OpenCanary - MSSQL Login Attempt Via SQLAuth\nid: 3ec9a16d-0b4f-4967-9542-ebf38ceac7dd\nstatus: test\ndescription: |\n    Detects instances where an MSSQL service on an OpenCanary node has had a login attempt using SQLAuth.\nreferences:\n    - https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration\n    - https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52\nauthor: Security Onion Solutions\ndate: 2024-03-08\ntags:\n    - attack.credential-access\n    - attack.collection\n    - attack.t1003\n    - attack.t1213\nlogsource:\n    category: application\n    product: opencanary\ndetection:\n    selection:\n        logtype: 9001\n    condition: selection\nfalsepositives:\n    - Unlikely\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1003","id":"T1003","name":"OS Credential Dumping","page":"techniques/enterprise/T1003/"},{"key":"enterprise/T1213","id":"T1213","name":"Data from Information Repositories","page":"techniques/enterprise/T1213/"}],"data_path":"data/detection-rules/3ec9a16d-0b4f-4967-9542-ebf38ceac7dd.json","kind":"sigma"}
