{"id":"65f77b1e-8e79-45bf-bb67-5988a8ce45a5","title":"SharpHound Recon Account Discovery","description":"Detects remote RPC calls useb by SharpHound to map remote connections and local group membership.","author":"Sagie Dulce, Dekel Paz","status":"test","level":"high","date":"2022-01-01","modified":"","tags":["attack.t1087","attack.discovery"],"technique_ids":["T1087"],"logsource":{"product":"rpc_firewall","category":"application","definition":"Requirements: install and apply the RPC Firewall to all processes with \"audit:true action:block uuid:6bffd098-a112-3610-9833-46c3f87e345a opnum:2"},"falsepositives":["Unknown"],"references":["https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-wkst/55118c55-2122-4ef9-8664-0c1ff9e168f3","https://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-WKST.md","https://github.com/zeronetworks/rpcfirewall","https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/"],"source_path":"rules/application/rpc_firewall/rpc_firewall_sharphound_recon_account.yml","source_sha256":"a16b6ec6df294cebf77b3fe9425618b5c45900ffb5b59b3be483ba3a03a6d951","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/application/rpc_firewall/rpc_firewall_sharphound_recon_account.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: SharpHound Recon Account Discovery\nid: 65f77b1e-8e79-45bf-bb67-5988a8ce45a5\nstatus: test\ndescription: Detects remote RPC calls useb by SharpHound to map remote connections and local group membership.\nreferences:\n    - https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-wkst/55118c55-2122-4ef9-8664-0c1ff9e168f3\n    - https://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-WKST.md\n    - https://github.com/zeronetworks/rpcfirewall\n    - https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/\nauthor: Sagie Dulce, Dekel Paz\ndate: 2022-01-01\ntags:\n    - attack.t1087\n    - attack.discovery\nlogsource:\n    product: rpc_firewall\n    category: application\n    definition: 'Requirements: install and apply the RPC Firewall to all processes with \"audit:true action:block uuid:6bffd098-a112-3610-9833-46c3f87e345a opnum:2'\ndetection:\n    selection:\n        EventLog: RPCFW\n        EventID: 3\n        InterfaceUuid: 6bffd098-a112-3610-9833-46c3f87e345a\n        OpNum: 2\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1087","id":"T1087","name":"Account Discovery","page":"techniques/enterprise/T1087/"}],"data_path":"data/detection-rules/65f77b1e-8e79-45bf-bb67-5988a8ce45a5.json","kind":"sigma"}
