LoFP LoFP / to be determined

Techniques

Sample rules

Esentutl Gather Credentials

Description

Conti recommendation to its affiliates to use esentutl to access NTDS dumped file. Trickbot also uses this utilities to get MSEdge info via its module pwgrab.

Detection logic

condition: selection
selection:
  CommandLine|contains|all:
  - esentutl
  - ' /p'