Skip to content

Hide Navigation Hide TOC

HackTool - CrackMapExec Execution (42a993dd-bb3e-48c8-b372-4d6684c4106c)

This rule detect common flag combinations used by CrackMapExec in order to detect its use even if the binary has been replaced.

Cluster A Galaxy A Cluster B Galaxy B Level
PowerShell - T1059.001 (970a3432-3237-47ad-bcca-7d8cbb217736) Attack Pattern HackTool - CrackMapExec Execution (42a993dd-bb3e-48c8-b372-4d6684c4106c) Sigma-Rules 1
HackTool - CrackMapExec Execution (42a993dd-bb3e-48c8-b372-4d6684c4106c) Sigma-Rules Brute Force - T1110 (a93494bb-4b80-4ea1-8695-3236a49916fd) Attack Pattern 1
Password Policy Discovery - T1201 (b6075259-dba3-44e9-87c7-e954f37ec0d5) Attack Pattern HackTool - CrackMapExec Execution (42a993dd-bb3e-48c8-b372-4d6684c4106c) Sigma-Rules 1
Windows Command Shell - T1059.003 (d1fcf083-a721-4223-aedf-bf8960798d62) Attack Pattern HackTool - CrackMapExec Execution (42a993dd-bb3e-48c8-b372-4d6684c4106c) Sigma-Rules 1
Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern HackTool - CrackMapExec Execution (42a993dd-bb3e-48c8-b372-4d6684c4106c) Sigma-Rules 1
Windows Management Instrumentation - T1047 (01a5a209-b94c-450b-b7f9-946497d91055) Attack Pattern HackTool - CrackMapExec Execution (42a993dd-bb3e-48c8-b372-4d6684c4106c) Sigma-Rules 1
PowerShell - T1059.001 (970a3432-3237-47ad-bcca-7d8cbb217736) Attack Pattern Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern 2
Windows Command Shell - T1059.003 (d1fcf083-a721-4223-aedf-bf8960798d62) Attack Pattern Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern 2