Last active
May 23, 2021 04:55
-
-
Save silence-is-best/435ddb388f872b1a2e332b6239e9150b to your computer and use it in GitHub Desktop.
Mimikatz CVE-2020-1472 Zerologon snort suricata
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
alert tcp any any -> any ![139,445] (msg:"Possible Mimikatz Zerologon Attempt"; flow:established,to_server; content:"|00|"; offset:2; content:"|0f 00|"; distance:22; within:2; fast_pattern; content:"|00 00 00 00 00 00 00 00 ff ff 2f 21|"; within:90; reference:url,https://github.com/gentilkiwi/mimikatz/releases/tag/2.2.0-20200916; classtype:attempted-admin; sid:20166330; rev:2; metadata:created_at 2020_09_19;) |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment