1200KM / detection
T1187 Forced Authentication — Detection Rules
Detection workspace for T1187 Forced Authentication: 7 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Potential PetitPotam Attack Via EFS RPC Calls · test · medium · {"product":"zeek","service":"dce_rpc"}
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing - Network · experimental · high · {"product":"zeek","service":"dns"}
- Possible PetitPotam Coerce Authentication Attempt · test · high · {"product":"windows","service":"security","definition":"The advanced audit policy setting \"Object Access > Detailed File Share\" must be configured for Success/Failure"}
- PetitPotam Suspicious Kerberos TGT Request · test · high · {"product":"windows","service":"security","definition":"The advanced audit policy setting \"Account Logon > Kerberos Authentication Service\" must be configured for Success/Failure"}
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing · experimental · high · {"product":"windows","category":"dns_query"}
- NTLM Hash Leak Via Curl NTLM Authentication · test · high · {"category":"process_creation","product":"windows"}
- Attempts of Kerberos Coercion Via DNS SPN Spoofing · experimental · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0022 Detect Forced SMB/WebDAV Authentication via lure files and outbound NTLM
AN0065 Analytic 0065
Adversary stages a lure that references a remote resource (e.g., LNK/SCF/Office template). When the user opens/renders the file or a shell enumerates icons, the host automatically attempts SMB or WebDAV authentication to the attacker host. The chain is: (1) lure file is created or modified in a user-exposed location → (2) user or system accesses the lure → (3) host makes outbound NTLM (SMB 139/445 or WebDAV over 80/443) to an untrusted destination → (4) repeated attempts from multiple users/hosts or from privileged workstations.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- File Creation · DC0039
- File Modification · DC0061
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.