Rules Contributing to Possible Impacket SecretDump Remote Activity Alert

The following rules detect suspicious SMB traffic related to credential dumping using Impacket. Any one or more of these will trigger the Possible Impacket SecretDump Remote Activity Alert. Details for each rule can be viewed by clicking the More Details link in the description.

Title

Description

Possible Impacket SecretDump Remote Activity

Detect AD credential dumping using Impacket SecretDump HKTL