Windows: Detect Rubeus.exe HackTool Execution via Command-Line Kerberos Actions
Flags Windows process executions of Rubeus.exe when command lines include Kerberos attack-related actions.
FreeUnreviewedSigmacriticalv1
windows-detect-rubeus-exe-hacktool-execution-via-command-line-kerberos-actions-7ec2c172
title: "Windows: Detect Rubeus.exe HackTool Execution via Command-Line Kerberos Actions"
id: 3321f85b-bb1b-41ee-ad5c-33d3acc2cf0f
related:
- id: 7ec2c172-dceb-4c10-92c9-87c1881b7e18
type: similar
- id: 7ec2c172-dceb-4c10-92c9-87c1881b7e18
type: derived
status: stable
description: This rule identifies execution of the Rubeus hacktool on Windows by matching Rubeus.exe process characteristics and a set of Kerberos-focused command-line arguments. Such tooling is commonly used to access or manipulate Kerberos artifacts (for example tickets, impersonation, and service account targeting), which can enable credential access and lateral movement. The detection relies on process creation telemetry, including the executable name and command-line contents.
references:
- https://blog.harmj0y.net/redteaming/from-kekeo-to-rubeus
- https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html
- https://github.com/GhostPack/Rubeus
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_rubeus.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2018-12-19
modified: 2023-04-20
tags:
- attack.credential-access
- attack.t1003
- attack.t1558.003
- attack.lateral-movement
- attack.t1550.003
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|endswith: \Rubeus.exe
- OriginalFileName: Rubeus.exe
- Description: Rubeus
- CommandLine|contains:
- "asreproast "
- "dump /service:krbtgt "
- dump /luid:0x
- "kerberoast "
- "createnetonly /program:"
- "ptt /ticket:"
- "/impersonateuser:"
- "renew /ticket:"
- "asktgt /user:"
- "harvest /interval:"
- "s4u /user:"
- "s4u /ticket:"
- "hash /password:"
- "golden /aes256:"
- "silver /user:"
condition: selection
falsepositives:
- Unlikely
level: critical
license: DRL-1.1
What it detects
This rule identifies execution of the Rubeus hacktool on Windows by matching Rubeus.exe process characteristics and a set of Kerberos-focused command-line arguments. Such tooling is commonly used to access or manipulate Kerberos artifacts (for example tickets, impersonation, and service account targeting), which can enable credential access and lateral movement. The detection relies on process creation telemetry, including the executable name and command-line contents.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.