Windows SharpLDAPmonitor HackTool Execution via Image Name and Credential/DC Flags

Flags SharpLDAPmonitor execution on Windows with LDAP-related command-line parameters.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-12-30
Updated
2026-07-31

What it detects

This rule identifies execution of SharpLDAPmonitor on Windows by matching the executable name and by observing command-line parameters consistent with LDAP access (including /user:, /pass:, and /dcip:). Monitoring or interacting with directory objects can support reconnaissance and change tracking, so detecting this tool execution helps surface attacker-driven LDAP activity. It relies on process creation telemetry, including the process image name and command-line arguments.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.