Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows LAPS Credential Dump via Entra ID #4846

Open
BIitzkrieg opened this issue May 8, 2024 · 1 comment
Open

Windows LAPS Credential Dump via Entra ID #4846

BIitzkrieg opened this issue May 8, 2024 · 1 comment
Assignees

Comments

@BIitzkrieg
Copy link

BIitzkrieg commented May 8, 2024

Description of the Idea of the Rule

Analytic that detects when an account dumps the LAPS password via Entra ID.

Public References / Example Event Log

[Additional references and logs if possible to ease the process of creating the rule]
https://twitter.com/NathanMcNulty/status/1785051227568632263


Detection Logic:

title: Windows LAPS Credential Dump via Entra ID
description: |
  This analytic detects when an account dumps the LAPS password via Entra ID.
author: andrewdanis
references:
  - https://twitter.com/NathanMcNulty/status/1785051227568632263
logsource:
  product: azure
  service: activitylogs
detection:
  condition: selection
  selection:
    Category: Device
    ActivityType: Recover device local administrator password
    AdditionalInfo: Successfully recovered local credential by device id
    Service: Device Registration Service
status: test
date: 2024/04/30
falsepositives:
  - Trusted activity performed by an Administrator.
level: high
tags:
  - 'T1098.005: Account Manipulation: Device Registration'
Copy link
Contributor

github-actions bot commented May 8, 2024

Welcome @BIitzkrieg 👋

It looks like this is your first issue on the Sigma rules repository!

The following repository accepts issues related to false positives or 'rule ideas'.

If you're reporting an issue related to the pySigma library please consider submitting it here

If you're reporting an issue related to the deprecated sigmac library please consider submitting it here

Thanks for taking the time to open this issue, and welcome to the Sigma community! 😃

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants