title: CrackMapExecWin author: Markus Neis date: 2018/04/08 description: Detects CrackMapExecWin Activity as Described by NCSC detection: SELECTION_1: EventID: 1 SELECTION_2: Image: - '*\crackmapexec.exe' condition: (SELECTION_1 and SELECTION_2) falsepositives: - None id: 04d9079e-3905-4b70-ad37-6bdf11304965 level: critical logsource: category: process_creation product: windows references: - https://www.ncsc.gov.uk/alerts/hostile-state-actors-compromising-uk-organisations-focus-engineering-and-industrial-control - https://attack.mitre.org/software/S0488/ status: experimental tags: - attack.g0035 - attack.credential_access - attack.discovery - attack.t1110 - attack.t1087 ruletype: SIGMA