Skip to content

Commit

Permalink
Update registry_event_net_ntlm_downgrade.yml
Browse files Browse the repository at this point in the history
  • Loading branch information
nasbench authored Dec 3, 2024
1 parent 7f2b3d2 commit b48b6ca
Showing 1 changed file with 20 additions and 11 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,8 @@ status: test
description: Detects NetNTLM downgrade attack
references:
- https://web.archive.org/web/20171113231705/https://www.optiv.com/blog/post-exploitation-using-netntlm-downgrade-attacks
author: Florian Roth (Nextron Systems), wagga
- https://www.ultimatewindowssecurity.com/wiki/page.aspx?spid=NSrpcservers
author: Florian Roth (Nextron Systems), wagga, Nasreddine Bencherchali (Splunk STRT)
date: 2018-03-20
modified: 2024-12-03
tags:
Expand All @@ -15,22 +16,30 @@ logsource:
product: windows
category: registry_event
detection:
selection:
selection_regkey:
TargetObject|contains|all:
- 'SYSTEM\'
- 'ControlSet'
- '\Control\Lsa'
selection_lmcompatibilitylevel:
selection_value_lmcompatibilitylevel:
TargetObject|endswith: '\lmcompatibilitylevel'
Details:
- 0
- 1
- 2
selection_ntlmminclientsec:
TargetObject|endswith:
- '\NtlmMinClientSec'
- '\RestrictSendingNTLMTraffic'
condition: selection and 1 of selection_*
- 'DWORD (0x00000000)'
- 'DWORD (0x00000001)'
- 'DWORD (0x00000002)'
selection_value_ntlmminclientsec:
TargetObject|endswith: '\NtlmMinClientSec'
Details:
- 'DWORD (0x00000000)' # No Security
- 'DWORD (0x00000010)' # Only Integrity
- 'DWORD (0x00000020)' # Only confidentiality
- 'DWORD (0x00000020)' # Both Integrity and confidentiality
selection_value_ntlmminclientsec:
# Note: The obvious values with issues are 0x00000000 (allow all) and 0x00000001 (audit).
# 0x00000002 can be secure but only if "ClientAllowedNTLMServers" is properly configured
# Hence all values should be monitored and investigated
TargetObject|endswith: '\RestrictSendingNTLMTraffic'
condition: selection_regkey and 1 of selection_value_*
falsepositives:
- Services or tools that set the values to more restrictive values
level: high

0 comments on commit b48b6ca

Please sign in to comment.