{"id":"6daac7fc-77d1-449a-a71a-e6b4d59a0e54","title":"User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess'","description":"The 'LsaRegisterLogonProcess' function verifies that the application making the function call is a logon process by checking that it has the SeTcbPrivilege privilege set. Possible Rubeus tries to get a handle to LSA.","author":"Roberto Rodriguez (source), Ilyas Ochkov (rule), oscd.community","status":"test","level":"high","date":"2019-10-24","modified":"2022-12-25","tags":["attack.credential-access","attack.lateral-movement","attack.privilege-escalation","attack.t1558.003"],"technique_ids":["T1558.003"],"logsource":{"product":"windows","service":"security"},"falsepositives":["Unknown"],"references":["https://posts.specterops.io/hunting-in-active-directory-unconstrained-delegation-forests-trusts-71f2b33688e1"],"source_path":"rules/windows/builtin/security/win_security_user_couldnt_call_priv_service_lsaregisterlogonprocess.yml","source_sha256":"1321d261169ac90e07f8f51059194fb0fdb8487d0ebb87435c7b9af6df24c8d1","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/security/win_security_user_couldnt_call_priv_service_lsaregisterlogonprocess.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess'\nid: 6daac7fc-77d1-449a-a71a-e6b4d59a0e54\nstatus: test\ndescription: The 'LsaRegisterLogonProcess' function verifies that the application making the function call is a logon process by checking that it has the SeTcbPrivilege privilege set. Possible Rubeus tries to get a handle to LSA.\nreferences:\n    - https://posts.specterops.io/hunting-in-active-directory-unconstrained-delegation-forests-trusts-71f2b33688e1\nauthor: Roberto Rodriguez (source), Ilyas Ochkov (rule), oscd.community\ndate: 2019-10-24\nmodified: 2022-12-25\ntags:\n    - attack.credential-access\n    - attack.lateral-movement\n    - attack.privilege-escalation\n    - attack.t1558.003\nlogsource:\n    product: windows\n    service: security\ndetection:\n    selection:\n        EventID: 4673\n        Service: 'LsaRegisterLogonProcess()'\n        Keywords: '0x8010000000000000'     # failure\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1558.003","id":"T1558.003","name":"Kerberoasting","page":"techniques/enterprise/T1558.003/"}],"data_path":"data/detection-rules/6daac7fc-77d1-449a-a71a-e6b4d59a0e54.json","kind":"sigma"}
