{"id":"68050b10-e477-4377-a99b-3721b422d6ef","title":"Remote DCOM/WMI Lateral Movement","description":"Detects remote RPC calls that performs remote DCOM operations. These could be abused for lateral movement via DCOM or WMI.","author":"Sagie Dulce, Dekel Paz","status":"test","level":"high","date":"2022-01-01","modified":"","tags":["attack.lateral-movement","attack.execution","attack.t1021.003","attack.t1047"],"technique_ids":["T1021.003","T1047"],"logsource":{"product":"rpc_firewall","category":"application","definition":"Requirements: install and apply the RPC Firewall to all processes with \"audit:true action:block uuid:367abb81-9844-35f1-ad32-98f038001003"},"falsepositives":["Some administrative tasks on remote host"],"references":["https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-srvs/accf23b0-0f57-441c-9185-43041f1b0ee9","https://github.com/zeronetworks/rpcfirewall","https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/"],"source_path":"rules/application/rpc_firewall/rpc_firewall_remote_dcom_or_wmi.yml","source_sha256":"166acc359843672d0708aca6e5c9212cd2089f90c6796444c4d92167ac09dc3a","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/application/rpc_firewall/rpc_firewall_remote_dcom_or_wmi.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Remote DCOM/WMI Lateral Movement\nid: 68050b10-e477-4377-a99b-3721b422d6ef\nstatus: test\ndescription: Detects remote RPC calls that performs remote DCOM operations. These could be abused for lateral movement via DCOM or WMI.\nreferences:\n    - https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-srvs/accf23b0-0f57-441c-9185-43041f1b0ee9\n    - https://github.com/zeronetworks/rpcfirewall\n    - https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/\nauthor: Sagie Dulce, Dekel Paz\ndate: 2022-01-01\ntags:\n    - attack.lateral-movement\n    - attack.execution\n    - attack.t1021.003\n    - attack.t1047\nlogsource:\n    product: rpc_firewall\n    category: application\n    definition: 'Requirements: install and apply the RPC Firewall to all processes with \"audit:true action:block uuid:367abb81-9844-35f1-ad32-98f038001003'\ndetection:\n    selection:\n        EventLog: RPCFW\n        EventID: 3\n        InterfaceUuid:\n            - 4d9f4ab8-7d1c-11cf-861e-0020af6e7c57\n            - 99fcfec4-5260-101b-bbcb-00aa0021347a\n            - 000001a0-0000-0000-c000-000000000046\n            - 00000131-0000-0000-c000-000000000046\n            - 00000143-0000-0000-c000-000000000046\n            - 00000000-0000-0000-c000-000000000046\n    condition: selection\nfalsepositives:\n    - Some administrative tasks on remote host\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1021.003","id":"T1021.003","name":"Distributed Component Object Model","page":"techniques/enterprise/T1021.003/"},{"key":"enterprise/T1047","id":"T1047","name":"Windows Management Instrumentation","page":"techniques/enterprise/T1047/"}],"data_path":"data/detection-rules/68050b10-e477-4377-a99b-3721b422d6ef.json","kind":"sigma"}
