Rules Contributing to Protected Storage Service Access Alert
The following rules detect suspicious SMB traffic accessing protected storage services. Any one or more of these will trigger the Protected Storage Service Access Alert. Details for each rule can be viewed by clicking the More Details link in the description.
Title |
Description |
||||||||
---|---|---|---|---|---|---|---|---|---|
Protected Storage Service Access |
Detects access to a protected_storage service over the network. Potential abuse of DPAPI to extract domain backup keys from Domain Controllers More details
Rule IDQuery{'selection': {'appid_name': 'smb', 'metadata|contains': ['protected_storage']}, 'condition': 'selection'} Log SourceStellar Cyber Network Events configured for:
Rule SourceDeveloped internally by Stellar Cyber Tactics, Techniques, and ProceduresReferencesSeverity75 Suppression Logic Based On
Additional Information
|