Rules Contributing to Possible PetitPotam Coerce Authentication Attempt Alert
The following rules detect suspicious SMB traffic related to PetitPotam coerced authentication. Any one or more of these will trigger the Possible PetitPotam Coerce Authentication Attempt Alert. Details for each rule can be viewed by clicking the More Details link in the description.
Title |
Description |
||||||||
---|---|---|---|---|---|---|---|---|---|
Possible PetitPotam Coerce Authentication Attempt |
Detect PetitPotam coerced authentication activity. More details
Rule IDQuery{'selection': {'appid_name': 'smb', 'metadata|contains|all': ['IPC$', 'lsarpc', 'ANONYMOUS LOGON']}, 'condition': 'selection'} Log SourceStellar Cyber Network Events configured for:
Rule SourceDeveloped internally by Stellar Cyber Tactics, Techniques, and ProceduresReferencesSeverity75 Suppression Logic Based On
Additional Information
|