LoFP LoFP / unknown. feedback welcomed.

Techniques

Sample rules

Possible PetitPotam Coerce Authentication Attempt

Description

Detect PetitPotam coerced authentication activity.

Detection logic

condition: selection
selection:
  EventID: 5145
  RelativeTargetName: lsarpc
  ShareName|endswith: \IPC$
  ShareName|startswith: \\\\
  SubjectUserName: ANONYMOUS LOGON