{"id":"e3818659-5016-4811-a73c-dde4679169d2","title":"Suspicious Computer Machine Password by PowerShell","description":"The Reset-ComputerMachinePassword cmdlet changes the computer account password that the computers use to authenticate to the domain controllers in the domain.\nYou can use it to reset the password of the local computer.\n","author":"frack113","status":"test","level":"medium","date":"2022-02-21","modified":"","tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078"],"technique_ids":["T1078"],"logsource":{"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"},"falsepositives":["Administrator PowerShell scripts"],"references":["https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/reset-computermachinepassword?view=powershell-5.1","https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/"],"source_path":"rules/windows/powershell/powershell_module/posh_pm_susp_reset_computermachinepassword.yml","source_sha256":"deffb142bc3259ed55d03a5db27aa352be2a586796aae78c6bf8d66bb060886d","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/powershell/powershell_module/posh_pm_susp_reset_computermachinepassword.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Suspicious Computer Machine Password by PowerShell\nid: e3818659-5016-4811-a73c-dde4679169d2\nstatus: test\ndescription: |\n    The Reset-ComputerMachinePassword cmdlet changes the computer account password that the computers use to authenticate to the domain controllers in the domain.\n    You can use it to reset the password of the local computer.\nreferences:\n    - https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/reset-computermachinepassword?view=powershell-5.1\n    - https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/\nauthor: frack113\ndate: 2022-02-21\ntags:\n    - attack.privilege-escalation\n    - attack.persistence\n    - attack.initial-access\n    - attack.stealth\n    - attack.t1078\nlogsource:\n    product: windows\n    category: ps_module\n    definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b\ndetection:\n    selection:\n        ContextInfo|contains: 'Reset-ComputerMachinePassword'\n    condition: selection\nfalsepositives:\n    - Administrator PowerShell scripts\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1078","id":"T1078","name":"Valid Accounts","page":"techniques/enterprise/T1078/"}],"data_path":"data/detection-rules/e3818659-5016-4811-a73c-dde4679169d2.json","kind":"sigma"}
