Windows: Detect Rubeus.exe HackTool Execution via Command-Line Kerberos Actions

Flags Windows process executions of Rubeus.exe when command lines include Kerberos attack-related actions.

FreeUnreviewedSigmacriticalv1
title: "Windows: Detect Rubeus.exe HackTool Execution via Command-Line Kerberos Actions"
id: 3321f85b-bb1b-41ee-ad5c-33d3acc2cf0f
related:
  - id: 7ec2c172-dceb-4c10-92c9-87c1881b7e18
    type: similar
  - id: 7ec2c172-dceb-4c10-92c9-87c1881b7e18
    type: derived
status: stable
description: This rule identifies execution of the Rubeus hacktool on Windows by matching Rubeus.exe process characteristics and a set of Kerberos-focused command-line arguments. Such tooling is commonly used to access or manipulate Kerberos artifacts (for example tickets, impersonation, and service account targeting), which can enable credential access and lateral movement. The detection relies on process creation telemetry, including the executable name and command-line contents.
references:
  - https://blog.harmj0y.net/redteaming/from-kekeo-to-rubeus
  - https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html
  - https://github.com/GhostPack/Rubeus
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_rubeus.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2018-12-19
modified: 2023-04-20
tags:
  - attack.credential-access
  - attack.t1003
  - attack.t1558.003
  - attack.lateral-movement
  - attack.t1550.003
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    - Image|endswith: \Rubeus.exe
    - OriginalFileName: Rubeus.exe
    - Description: Rubeus
    - CommandLine|contains:
        - "asreproast "
        - "dump /service:krbtgt "
        - dump /luid:0x
        - "kerberoast "
        - "createnetonly /program:"
        - "ptt /ticket:"
        - "/impersonateuser:"
        - "renew /ticket:"
        - "asktgt /user:"
        - "harvest /interval:"
        - "s4u /user:"
        - "s4u /ticket:"
        - "hash /password:"
        - "golden /aes256:"
        - "silver /user:"
  condition: selection
falsepositives:
  - Unlikely
level: critical
license: DRL-1.1

What it detects

This rule identifies execution of the Rubeus hacktool on Windows by matching Rubeus.exe process characteristics and a set of Kerberos-focused command-line arguments. Such tooling is commonly used to access or manipulate Kerberos artifacts (for example tickets, impersonation, and service account targeting), which can enable credential access and lateral movement. The detection relies on process creation telemetry, including the executable name and command-line contents.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.