LoFP LoFP / transferring sensitive files for legitimate administration work by legitimate administrator

Techniques

Sample rules

Transferring Files with Credential Data via Network Shares - Zeek

Description

Transferring files with well-known filenames (sensitive files with credential data) using network shares

Detection logic

condition: selection
selection:
  name:
  - \mimidrv
  - \lsass
  - \windows\minidump\
  - \hiberfil
  - \sqldmpr
  - \sam
  - \ntds.dit
  - \security

Transferring Files with Credential Data via Network Shares

Description

Transferring files with well-known filenames (sensitive files with credential data) using network shares

Detection logic

condition: selection
selection:
  EventID: 5145
  RelativeTargetName|contains:
  - \mimidrv
  - \lsass
  - \windows\minidump\
  - \hiberfil
  - \sqldmpr
  - \sam
  - \ntds.dit
  - \security