Windows: Detect KrbRelayUp.exe HackTool Process Execution

Flags Windows process executions of KrbRelayUp.exe with relay/domain and SCM spawn command-line patterns.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-04-26
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows process creation where the executable name or original filename indicates KrbRelayUp, and the command line contains multiple KrbRelayUp-specific argument patterns. KrbRelayUp is a credential- and privilege-impacting utility used to perform local privilege escalation in certain domain configurations. It relies on process creation telemetry, including the image path/name and the full command line arguments.

Related detections9 linkedT1558.003 — drag to rearrange
Rubeus HackTool Execution via PowerShell ScriptBlock Flags (Windows)
Windows Process Creation: Rubeus HackTool Execution Indicators
Malicious Kerberos Ticket File Creation Indicating Credential Theft (via file_event)
Suspicious Kerberoasting via setspn Service Principal Query
Masquerading Kerberos Ticket Abuse via Rubeus (via process_creation)
Possible Targeted Kerberoasting via servicePrincipalName Modification
Suspicious SQL Service Principal Name Enumeration via Setspn
Windows: Suspicious Kerberos Ticket Requests from PowerShell Using KerberosRequestorSecurityToken
Windows Process Creation: RemoteKrbRelay Kerberos Relay Tool Execution
Windows: Detect KrbRelayUp.exe HackTool Process Execution
Pivot detection · T1558.003 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.