Windows Process Creation: CrackMapExec execution via distinctive command-line flags
Alerts on Windows process creation showing CrackMapExec-style command-line flags for local auth and module execution.
FreeUnreviewedSigmahighv1
windows-process-creation-crackmapexec-execution-via-distinctive-command-line-fla-42a993dd
title: "Windows Process Creation: CrackMapExec execution via distinctive command-line flags"
id: bd0eca4e-dc2f-49b8-8387-d4eeaa39009b
status: test
description: This rule flags Windows process creation events where the command line matches common CrackMapExec options, including module usage and local authentication parameters, even when the executable path has changed (it does not rely solely on the binary name). Attackers use CrackMapExec for credential checking and remote service interaction, and its consistent flag combinations make it a useful behavioral indicator. Telemetry relies on process creation fields including Image ending with crackmapexec.exe and CommandLine substring matches for specific arguments.
references:
- https://mpgn.gitbook.io/crackmapexec/smb-protocol/authentication/checking-credentials-local
- https://www.mandiant.com/resources/telegram-malware-iranian-espionage
- https://www.infosecmatter.com/crackmapexec-module-library/?cmem=mssql-mimikatz
- https://www.infosecmatter.com/crackmapexec-module-library/?cmem=smb-pe_inject
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_crackmapexec_execution.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-02-25
modified: 2023-03-08
tags:
- attack.execution
- attack.persistence
- attack.privilege-escalation
- attack.credential-access
- attack.discovery
- attack.t1047
- attack.t1053
- attack.t1059.003
- attack.t1059.001
- attack.t1110
- attack.t1201
logsource:
category: process_creation
product: windows
detection:
selection_binary:
Image|endswith: \crackmapexec.exe
selection_special:
CommandLine|contains: " -M pe_inject "
selection_execute:
CommandLine|contains|all:
- " --local-auth"
- " -u "
- " -x "
selection_hash:
CommandLine|contains|all:
- " --local-auth"
- " -u "
- " -p "
- " -H 'NTHASH'"
selection_module_mssql:
CommandLine|contains|all:
- " mssql "
- " -u "
- " -p "
- " -M "
- " -d "
selection_module_smb1:
CommandLine|contains|all:
- " smb "
- " -u "
- " -H "
- " -M "
- " -o "
selection_module_smb2:
CommandLine|contains|all:
- " smb "
- " -u "
- " -p "
- " --local-auth"
part_localauth_1:
CommandLine|contains|all:
- " --local-auth"
- " -u "
- " -p "
part_localauth_2:
CommandLine|contains|all:
- " 10."
- " 192.168."
- "/24 "
condition: 1 of selection_* or all of part_localauth*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 42a993dd-bb3e-48c8-b372-4d6684c4106c
type: derived
What it detects
This rule flags Windows process creation events where the command line matches common CrackMapExec options, including module usage and local authentication parameters, even when the executable path has changed (it does not rely solely on the binary name). Attackers use CrackMapExec for credential checking and remote service interaction, and its consistent flag combinations make it a useful behavioral indicator. Telemetry relies on process creation fields including Image ending with crackmapexec.exe and CommandLine substring matches for specific arguments.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.