Rubeus HackTool Execution via PowerShell ScriptBlock Flags (Windows)

Identifies PowerShell ScriptBlock content that includes Rubeus-specific Kerberos and ticket manipulation flags.

FreeReviewedSigma · High · v2
Product
windows
Category
ps_script
Author
Christian Burkard (Nextron Systems), Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-04-27
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags PowerShell ScriptBlock content that includes command-line style flags associated with the Rubeus Kerberos-focused tool. Attackers use Rubeus to perform credential access and lateral movement actions such as ticket roasting/renewal, impersonation, and pass-the-ticket behavior. Detection relies on Script Block Logging telemetry capturing the executed script text and matching specific flag strings within it.

Related detections9 linkedT1003 — drag to rearrange
Windows Process Creation: Rubeus HackTool Execution Indicators
Windows: Detect KrbRelayUp.exe HackTool Process Execution
Malicious Wdigest Authentication Enabled - Reg via Command (via process_creation)
Malicious Diskshadow Command Abuse to Expose VSS Backup (via process_creation)
Malicious Kerberos Ticket File Creation Indicating Credential Theft (via file_event)
Malicious IIS Application Pool Credential Dumping (via process_creation)
Malicious Wdigest Authentication Enabled - Registry (via registry_set)
Suspicious Kerberoasting via setspn Service Principal Query
Masquerading Kerberos Ticket Abuse via Rubeus (via process_creation)
Rubeus HackTool Execution via PowerShell ScriptBlock Flags (Windows)
Pivot detection · T1003 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.