{"id":"a0cb7110-edf0-47a4-9177-541a4083128a","title":"Vulnerable Netlogon Secure Channel Connection Allowed","description":"Detects that a vulnerable Netlogon secure channel connection was allowed, which could be an indicator of CVE-2020-1472.","author":"NVISO","status":"test","level":"high","date":"2020-09-15","modified":"2022-12-25","tags":["attack.privilege-escalation","attack.t1548"],"technique_ids":["T1548"],"logsource":{"product":"windows","service":"system"},"falsepositives":["Unknown"],"references":["https://support.microsoft.com/en-us/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc"],"source_path":"rules/windows/builtin/system/netlogon/win_system_vul_cve_2020_1472.yml","source_sha256":"1ce7d283376a4fbc19955ea84aebed0c633041abca8870bf9ddaecc030246088","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/system/netlogon/win_system_vul_cve_2020_1472.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Vulnerable Netlogon Secure Channel Connection Allowed\nid: a0cb7110-edf0-47a4-9177-541a4083128a\nstatus: test\ndescription: Detects that a vulnerable Netlogon secure channel connection was allowed, which could be an indicator of CVE-2020-1472.\nreferences:\n    - https://support.microsoft.com/en-us/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc\nauthor: NVISO\ndate: 2020-09-15\nmodified: 2022-12-25\ntags:\n    - attack.privilege-escalation\n    - attack.t1548\nlogsource:\n    product: windows\n    service: system\ndetection:\n    selection:\n        Provider_Name: NetLogon  # Active Directory: NetLogon ETW GUID {F33959B4-DBEC-11D2-895B-00C04F79AB69}\n        EventID: 5829\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1548","id":"T1548","name":"Abuse Elevation Control Mechanism","page":"techniques/enterprise/T1548/"}],"data_path":"data/detection-rules/a0cb7110-edf0-47a4-9177-541a4083128a.json","kind":"sigma"}
