Outbound Network Connection To Public IP Via Winlogon

Rule Info

Name
Outbound Network Connection To Public IP Via Winlogon
Author
Christopher Peacock @securepeacock, SCYTHE @scythe_io
Description
Detects a "winlogon.exe" process that initiate network communications with public IP addresses
Date
2023-04-28 00:00:00
Modified
2024-03-12 00:00:00
Id
7610a4ea-c06d-495f-a2ac-0a696abcfd3b
Tags
attack.defense-evasion attack.execution attack.command-and-control attack.t1218.011
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
frack113
Merge PR #4765 from @frack113 - Update additional rules to use the `cidr` modifier
2024-03-13
Nasreddine Bencherchali
Merge PR #4761 from @nasbench - Update rules to use CIDR modifier
2024-03-11
github-actions[bot]
Merge PR #4745 from @nasbench - Promote older rules status from `experimental` to `test`
2024-03-01
Nasreddine Bencherchali
Update net_connection_win_winlogon_net_connections.yml
2023-04-28
Nasreddine Bencherchali
fix: small updates
2023-04-28
securepeacock
Update net_connection_win_winlogon_net_connections.yml
2023-04-28
securepeacock
Create net_connection_win_winlogon_net_connections.yml
2023-04-28
Florian Roth
fix: FPs with cloudapp
2023-02-05
Nasreddine Bencherchali
chore: add nextron authors tag
2023-02-01
frack113
Fix invalid field cast or name (#3841)
2022-12-30
Nasreddine Bencherchali
fix: broken single item lists
2022-12-08
frack113
Order yaml field
2022-10-26
Florian Roth
fix: FPs with MS IPs
2022-10-04
Florian Roth
fix: FPs noticed with Aurora
2022-05-02