LoFP LoFP / administrative scripts using explicit credentials from non-standard paths

Techniques

Sample rules

Potentially Suspicious Explicit Credential Local Logon

Description

Detects potentially suspicious explicit credential logon events where the user is trying to logon with explicit credentials (username and password) that are different from the current user context. It might indicate an attacker attempting to escalate privileges after obtaining credentials for a different user account.

Detection logic

condition: all of selection_* and not 1 of filter_main_*
filter_main_computer_accounts:
  SubjectUserName|endswith: $
filter_main_program_files:
  ProcessName|startswith:
  - C:\Program Files\
  - C:\Program Files (x86)\
filter_main_same_user:
  SubjectUserName|fieldref: TargetUserName
filter_main_system_processes:
  ProcessName|startswith:
  - C:\Windows\System32\
  - C:\Windows\SysWOW64\
  - C:\Windows\WinSxS\
selection_eid:
  EventID: 4648
selection_localhost:
- TargetServerName: localhost
- TargetInfo: localhost
- IpAddress:
  - 127.0.0.1
  - ::1