{"id":"b2317cfa-4a47-4ead-b3ff-297438c0bc2d","title":"HackTool - SharpView Execution","description":"Adversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems","author":"frack113","status":"test","level":"high","date":"2021-12-10","modified":"2023-02-14","tags":["attack.discovery","attack.t1049","attack.t1069.002","attack.t1482","attack.t1135","attack.t1033"],"technique_ids":["T1033","T1049","T1069.002","T1135","T1482"],"logsource":{"category":"process_creation","product":"windows"},"falsepositives":["Unknown"],"references":["https://github.com/tevora-threat/SharpView/","https://github.com/PowerShellMafia/PowerSploit/blob/d943001a7defb5e0d1657085a77a0e78609be58f/Recon/PowerView.ps1","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1049/T1049.md#atomic-test-4---system-discovery-using-sharpview"],"source_path":"rules/windows/process_creation/proc_creation_win_hktl_sharpview.yml","source_sha256":"da107f480a776ef25bc006d2171a5ac6564881c46c924b9885e9ed5921358b98","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_hktl_sharpview.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: HackTool - SharpView Execution\nid: b2317cfa-4a47-4ead-b3ff-297438c0bc2d\nrelated:\n    - id: dcd74b95-3f36-4ed9-9598-0490951643aa\n      type: similar\nstatus: test\ndescription: Adversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems\nreferences:\n    - https://github.com/tevora-threat/SharpView/\n    - https://github.com/PowerShellMafia/PowerSploit/blob/d943001a7defb5e0d1657085a77a0e78609be58f/Recon/PowerView.ps1\n    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1049/T1049.md#atomic-test-4---system-discovery-using-sharpview\nauthor: frack113\ndate: 2021-12-10\nmodified: 2023-02-14\ntags:\n    - attack.discovery\n    - attack.t1049\n    - attack.t1069.002\n    - attack.t1482\n    - attack.t1135\n    - attack.t1033\nlogsource:\n    category: process_creation\n    product: windows\ndetection:\n    selection:\n        - OriginalFileName: 'SharpView.exe'\n        - Image|endswith: '\\SharpView.exe'\n        - CommandLine|contains:\n              # - 'Add-DomainGroupMember'\n              # - 'Add-DomainObjectAcl'\n              # - 'Add-ObjectAcl'\n              - 'Add-RemoteConnection'\n              - 'Convert-ADName'\n              - 'ConvertFrom-SID'\n              - 'ConvertFrom-UACValue'\n              - 'Convert-SidToName'\n              # - 'ConvertTo-SID'\n              - 'Export-PowerViewCSV'\n              # - 'Find-DomainLocalGroupMember'\n              - 'Find-DomainObjectPropertyOutlier'\n              - 'Find-DomainProcess'\n              - 'Find-DomainShare'\n              - 'Find-DomainUserEvent'\n              - 'Find-DomainUserLocation'\n              - 'Find-ForeignGroup'\n              - 'Find-ForeignUser'\n              - 'Find-GPOComputerAdmin'\n              - 'Find-GPOLocation'\n              - 'Find-Interesting' # 'Find-InterestingDomainAcl', 'Find-InterestingDomainShareFile', 'Find-InterestingFile'\n              - 'Find-LocalAdminAccess'\n              - 'Find-ManagedSecurityGroups'\n              # - 'Get-ADObject'\n              - 'Get-CachedRDPConnection'\n              - 'Get-DFSshare'\n              # - 'Get-DNSRecord'\n              # - 'Get-DNSZone'\n              # - 'Get-Domain'\n              - 'Get-DomainComputer'\n              - 'Get-DomainController'\n              - 'Get-DomainDFSShare'\n              - 'Get-DomainDNSRecord'\n              # - 'Get-DomainDNSZone'\n              - 'Get-DomainFileServer'\n              - 'Get-DomainForeign' # 'Get-DomainForeignGroupMember', 'Get-DomainForeignUser'\n              - 'Get-DomainGPO' # 'Get-DomainGPOComputerLocalGroupMapping', 'Get-DomainGPOLocalGroup', 'Get-DomainGPOUserLocalGroupMapping'\n              - 'Get-DomainGroup' # 'Get-DomainGroupMember'\n              - 'Get-DomainGUIDMap'\n              - 'Get-DomainManagedSecurityGroup'\n              - 'Get-DomainObject' # 'Get-DomainObjectAcl'\n              - 'Get-DomainOU'\n              - 'Get-DomainPolicy' # 'Get-DomainPolicyData'\n              - 'Get-DomainSID'\n              - 'Get-DomainSite'\n              - 'Get-DomainSPNTicket'\n              - 'Get-DomainSubnet'\n              - 'Get-DomainTrust' # 'Get-DomainTrustMapping'\n              # - 'Get-DomainUser'\n              - 'Get-DomainUserEvent'\n              # - 'Get-Forest'\n              - 'Get-ForestDomain'\n              - 'Get-ForestGlobalCatalog'\n              - 'Get-ForestTrust'\n              - 'Get-GptTmpl'\n              - 'Get-GroupsXML'\n              # - 'Get-GUIDMap'\n              # - 'Get-IniContent'\n              # - 'Get-IPAddress'\n              - 'Get-LastLoggedOn'\n              - 'Get-LoggedOnLocal'\n              - 'Get-NetComputer' # 'Get-NetComputerSiteName'\n              - 'Get-NetDomain' # 'Get-NetDomainController', 'Get-NetDomainTrust'\n              - 'Get-NetFileServer'\n              - 'Get-NetForest' # 'Get-NetForestCatalog', 'Get-NetForestDomain', 'Get-NetForestTrust'\n              - 'Get-NetGPO' # 'Get-NetGPOGroup'\n              # - 'Get-NetGroup'\n              - 'Get-NetGroupMember'\n              - 'Get-NetLocalGroup' # 'Get-NetLocalGroupMember'\n              - 'Get-NetLoggedon'\n              - 'Get-NetOU'\n              - 'Get-NetProcess'\n              - 'Get-NetRDPSession'\n              - 'Get-NetSession'\n              - 'Get-NetShare'\n              - 'Get-NetSite'\n              - 'Get-NetSubnet'\n              - 'Get-NetUser'\n              # - 'Get-ObjectAcl'\n              - 'Get-PathAcl'\n              - 'Get-PrincipalContext'\n              # - 'Get-Proxy'\n              - 'Get-RegistryMountedDrive'\n              - 'Get-RegLoggedOn'\n              # - 'Get-SiteName'\n              # - 'Get-UserEvent'\n              # - 'Get-WMIProcess'\n              - 'Get-WMIRegCachedRDPConnection'\n              - 'Get-WMIRegLastLoggedOn'\n              - 'Get-WMIRegMountedDrive'\n              - 'Get-WMIRegProxy'\n              - 'Invoke-ACLScanner'\n              - 'Invoke-CheckLocalAdminAccess'\n              - 'Invoke-Kerberoast'\n              - 'Invoke-MapDomainTrust'\n              - 'Invoke-RevertToSelf'\n              - 'Invoke-Sharefinder'\n              - 'Invoke-UserImpersonation'\n              # - 'New-DomainGroup'\n              # - 'New-DomainUser'\n              - 'Remove-DomainObjectAcl'\n              - 'Remove-RemoteConnection'\n              - 'Request-SPNTicket'\n              # - 'Resolve-IPAddress'\n              # - 'Set-ADObject'\n              - 'Set-DomainObject'\n              # - 'Set-DomainUserPassword'\n              - 'Test-AdminAccess'\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1033","id":"T1033","name":"System Owner/User Discovery","page":"techniques/enterprise/T1033/"},{"key":"enterprise/T1049","id":"T1049","name":"System Network Connections Discovery","page":"techniques/enterprise/T1049/"},{"key":"enterprise/T1069.002","id":"T1069.002","name":"Domain Groups","page":"techniques/enterprise/T1069.002/"},{"key":"enterprise/T1135","id":"T1135","name":"Network Share Discovery","page":"techniques/enterprise/T1135/"},{"key":"enterprise/T1482","id":"T1482","name":"Domain Trust Discovery","page":"techniques/enterprise/T1482/"}],"data_path":"data/detection-rules/b2317cfa-4a47-4ead-b3ff-297438c0bc2d.json","kind":"sigma"}
