{"id":"6d580420-ff3f-4e0e-b6b0-41b90c787e28","title":"SharpHound Recon Sessions","description":"Detects remote RPC calls useb by SharpHound to map remote connections and local group membership.","author":"Sagie Dulce, Dekel Paz","status":"test","level":"high","date":"2022-01-01","modified":"","tags":["attack.discovery","attack.t1033"],"technique_ids":["T1033"],"logsource":{"product":"rpc_firewall","category":"application","definition":"Requirements: install and apply the RPC Firewall to all processes with \"audit:true action:block uuid:4b324fc8-1670-01d3-1278-5a47bf6ee188 opnum:12"},"falsepositives":["Unknown"],"references":["https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-srvs/02b1f559-fda2-4ba3-94c2-806eb2777183","https://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-SRVS.md","https://github.com/zeronetworks/rpcfirewall","https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/"],"source_path":"rules/application/rpc_firewall/rpc_firewall_sharphound_recon_sessions.yml","source_sha256":"fa4d4df0a234c8439d332a3fb1ae186460f409b02605caf8a71338fedec6a297","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/application/rpc_firewall/rpc_firewall_sharphound_recon_sessions.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: SharpHound Recon Sessions\nid: 6d580420-ff3f-4e0e-b6b0-41b90c787e28\nstatus: test\ndescription: Detects remote RPC calls useb by SharpHound to map remote connections and local group membership.\nreferences:\n    - https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-srvs/02b1f559-fda2-4ba3-94c2-806eb2777183\n    - https://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-SRVS.md\n    - https://github.com/zeronetworks/rpcfirewall\n    - https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/\nauthor: Sagie Dulce, Dekel Paz\ndate: 2022-01-01\ntags:\n    - attack.discovery\n    - attack.t1033\nlogsource:\n    product: rpc_firewall\n    category: application\n    definition: 'Requirements: install and apply the RPC Firewall to all processes with \"audit:true action:block uuid:4b324fc8-1670-01d3-1278-5a47bf6ee188 opnum:12'\ndetection:\n    selection:\n        EventLog: RPCFW\n        EventID: 3\n        InterfaceUuid: 4b324fc8-1670-01d3-1278-5a47bf6ee188\n        OpNum: 12\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1033","id":"T1033","name":"System Owner/User Discovery","page":"techniques/enterprise/T1033/"}],"data_path":"data/detection-rules/6d580420-ff3f-4e0e-b6b0-41b90c787e28.json","kind":"sigma"}
