Skip to content

Commit 0341294

Browse files
CHIRAG-DAMANI-08swachchhanda000phantinuss
authored
Merge PR #5922 from @CHIRAG-DAMANI-08 - Hacktool - NetExec Execution
new: HackTool - NetExec File Indicators new: Hacktool - NetExec Execution --------- Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com> Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
1 parent c801be9 commit 0341294

8 files changed

Lines changed: 525 additions & 0 deletions

File tree

Original file line numberDiff line numberDiff line change
@@ -0,0 +1,357 @@
1+
{
2+
"Event": {
3+
"#attributes": {
4+
"xmlns": "http://schemas.microsoft.com/win/2004/08/events/event"
5+
},
6+
"System": {
7+
"Provider": {
8+
"#attributes": {
9+
"Name": "Microsoft-Windows-Sysmon",
10+
"Guid": "5770385F-C22A-43E0-BF4C-06F5698FFBD9"
11+
}
12+
},
13+
"EventID": 11,
14+
"Version": 2,
15+
"Level": 4,
16+
"Task": 11,
17+
"Opcode": 0,
18+
"Keywords": "0x8000000000000000",
19+
"TimeCreated": {
20+
"#attributes": {
21+
"SystemTime": "2026-04-08T10:58:04.850672Z"
22+
}
23+
},
24+
"EventRecordID": 129825,
25+
"Correlation": null,
26+
"Execution": {
27+
"#attributes": {
28+
"ProcessID": 4584,
29+
"ThreadID": 5116
30+
}
31+
},
32+
"Channel": "Microsoft-Windows-Sysmon/Operational",
33+
"Computer": "swachchhanda",
34+
"Security": {
35+
"#attributes": {
36+
"UserID": "S-1-5-18"
37+
}
38+
}
39+
},
40+
"EventData": {
41+
"RuleName": "-",
42+
"UtcTime": "2026-04-08 10:58:04.846",
43+
"ProcessGuid": "0197231E-34BB-69D6-730F-000000000D00",
44+
"ProcessId": 12184,
45+
"Image": "C:\\Users\\xodih\\Downloads\\nxc-windows-latest\\nxc.exe",
46+
"TargetFilename": "C:\\Users\\xodih\\AppData\\Local\\Temp\\_MEI121842\\nxc\\data\\keepass_trigger_module\\RestartKeePass.ps1",
47+
"CreationUtcTime": "2026-04-08 10:58:04.846",
48+
"User": "swachchhanda\\xodih"
49+
}
50+
}
51+
}
52+
{
53+
"Event": {
54+
"#attributes": {
55+
"xmlns": "http://schemas.microsoft.com/win/2004/08/events/event"
56+
},
57+
"System": {
58+
"Provider": {
59+
"#attributes": {
60+
"Name": "Microsoft-Windows-Sysmon",
61+
"Guid": "5770385F-C22A-43E0-BF4C-06F5698FFBD9"
62+
}
63+
},
64+
"EventID": 11,
65+
"Version": 2,
66+
"Level": 4,
67+
"Task": 11,
68+
"Opcode": 0,
69+
"Keywords": "0x8000000000000000",
70+
"TimeCreated": {
71+
"#attributes": {
72+
"SystemTime": "2026-04-08T10:58:04.850722Z"
73+
}
74+
},
75+
"EventRecordID": 129826,
76+
"Correlation": null,
77+
"Execution": {
78+
"#attributes": {
79+
"ProcessID": 4584,
80+
"ThreadID": 5116
81+
}
82+
},
83+
"Channel": "Microsoft-Windows-Sysmon/Operational",
84+
"Computer": "swachchhanda",
85+
"Security": {
86+
"#attributes": {
87+
"UserID": "S-1-5-18"
88+
}
89+
}
90+
},
91+
"EventData": {
92+
"RuleName": "-",
93+
"UtcTime": "2026-04-08 10:58:04.848",
94+
"ProcessGuid": "0197231E-34BB-69D6-730F-000000000D00",
95+
"ProcessId": 12184,
96+
"Image": "C:\\Users\\xodih\\Downloads\\nxc-windows-latest\\nxc.exe",
97+
"TargetFilename": "C:\\Users\\xodih\\AppData\\Local\\Temp\\_MEI121842\\nxc\\data\\msol_dump\\entra-sync-creds.ps1",
98+
"CreationUtcTime": "2026-04-08 10:58:04.848",
99+
"User": "swachchhanda\\xodih"
100+
}
101+
}
102+
}
103+
{
104+
"Event": {
105+
"#attributes": {
106+
"xmlns": "http://schemas.microsoft.com/win/2004/08/events/event"
107+
},
108+
"System": {
109+
"Provider": {
110+
"#attributes": {
111+
"Name": "Microsoft-Windows-Sysmon",
112+
"Guid": "5770385F-C22A-43E0-BF4C-06F5698FFBD9"
113+
}
114+
},
115+
"EventID": 11,
116+
"Version": 2,
117+
"Level": 4,
118+
"Task": 11,
119+
"Opcode": 0,
120+
"Keywords": "0x8000000000000000",
121+
"TimeCreated": {
122+
"#attributes": {
123+
"SystemTime": "2026-04-08T10:58:04.864253Z"
124+
}
125+
},
126+
"EventRecordID": 129827,
127+
"Correlation": null,
128+
"Execution": {
129+
"#attributes": {
130+
"ProcessID": 4584,
131+
"ThreadID": 5116
132+
}
133+
},
134+
"Channel": "Microsoft-Windows-Sysmon/Operational",
135+
"Computer": "swachchhanda",
136+
"Security": {
137+
"#attributes": {
138+
"UserID": "S-1-5-18"
139+
}
140+
}
141+
},
142+
"EventData": {
143+
"RuleName": "-",
144+
"UtcTime": "2026-04-08 10:58:04.850",
145+
"ProcessGuid": "0197231E-34BB-69D6-730F-000000000D00",
146+
"ProcessId": 12184,
147+
"Image": "C:\\Users\\xodih\\Downloads\\nxc-windows-latest\\nxc.exe",
148+
"TargetFilename": "C:\\Users\\xodih\\AppData\\Local\\Temp\\_MEI121842\\nxc\\data\\ntds-dump-raw\\ntds-dump-raw.ps1",
149+
"CreationUtcTime": "2026-04-08 10:58:04.850",
150+
"User": "swachchhanda\\xodih"
151+
}
152+
}
153+
}
154+
{
155+
"Event": {
156+
"#attributes": {
157+
"xmlns": "http://schemas.microsoft.com/win/2004/08/events/event"
158+
},
159+
"System": {
160+
"Provider": {
161+
"#attributes": {
162+
"Name": "Microsoft-Windows-Sysmon",
163+
"Guid": "5770385F-C22A-43E0-BF4C-06F5698FFBD9"
164+
}
165+
},
166+
"EventID": 11,
167+
"Version": 2,
168+
"Level": 4,
169+
"Task": 11,
170+
"Opcode": 0,
171+
"Keywords": "0x8000000000000000",
172+
"TimeCreated": {
173+
"#attributes": {
174+
"SystemTime": "2026-04-08T10:58:04.864398Z"
175+
}
176+
},
177+
"EventRecordID": 129828,
178+
"Correlation": null,
179+
"Execution": {
180+
"#attributes": {
181+
"ProcessID": 4584,
182+
"ThreadID": 5116
183+
}
184+
},
185+
"Channel": "Microsoft-Windows-Sysmon/Operational",
186+
"Computer": "swachchhanda",
187+
"Security": {
188+
"#attributes": {
189+
"UserID": "S-1-5-18"
190+
}
191+
}
192+
},
193+
"EventData": {
194+
"RuleName": "EXE",
195+
"UtcTime": "2026-04-08 10:58:04.860",
196+
"ProcessGuid": "0197231E-34BB-69D6-730F-000000000D00",
197+
"ProcessId": 12184,
198+
"Image": "C:\\Users\\xodih\\Downloads\\nxc-windows-latest\\nxc.exe",
199+
"TargetFilename": "C:\\Users\\xodih\\AppData\\Local\\Temp\\_MEI121842\\nxc\\data\\procdump\\procdump.exe",
200+
"CreationUtcTime": "2026-04-08 10:58:04.860",
201+
"User": "swachchhanda\\xodih"
202+
}
203+
}
204+
}
205+
{
206+
"Event": {
207+
"#attributes": {
208+
"xmlns": "http://schemas.microsoft.com/win/2004/08/events/event"
209+
},
210+
"System": {
211+
"Provider": {
212+
"#attributes": {
213+
"Name": "Microsoft-Windows-Sysmon",
214+
"Guid": "5770385F-C22A-43E0-BF4C-06F5698FFBD9"
215+
}
216+
},
217+
"EventID": 11,
218+
"Version": 2,
219+
"Level": 4,
220+
"Task": 11,
221+
"Opcode": 0,
222+
"Keywords": "0x8000000000000000",
223+
"TimeCreated": {
224+
"#attributes": {
225+
"SystemTime": "2026-04-08T10:58:04.880069Z"
226+
}
227+
},
228+
"EventRecordID": 129829,
229+
"Correlation": null,
230+
"Execution": {
231+
"#attributes": {
232+
"ProcessID": 4584,
233+
"ThreadID": 5116
234+
}
235+
},
236+
"Channel": "Microsoft-Windows-Sysmon/Operational",
237+
"Computer": "swachchhanda",
238+
"Security": {
239+
"#attributes": {
240+
"UserID": "S-1-5-18"
241+
}
242+
}
243+
},
244+
"EventData": {
245+
"RuleName": "-",
246+
"UtcTime": "2026-04-08 10:58:04.876",
247+
"ProcessGuid": "0197231E-34BB-69D6-730F-000000000D00",
248+
"ProcessId": 12184,
249+
"Image": "C:\\Users\\xodih\\Downloads\\nxc-windows-latest\\nxc.exe",
250+
"TargetFilename": "C:\\Users\\xodih\\AppData\\Local\\Temp\\_MEI121842\\nxc\\data\\veeam_dump_module\\veeam_dump_mssql.ps1",
251+
"CreationUtcTime": "2026-04-08 10:58:04.876",
252+
"User": "swachchhanda\\xodih"
253+
}
254+
}
255+
}
256+
{
257+
"Event": {
258+
"#attributes": {
259+
"xmlns": "http://schemas.microsoft.com/win/2004/08/events/event"
260+
},
261+
"System": {
262+
"Provider": {
263+
"#attributes": {
264+
"Name": "Microsoft-Windows-Sysmon",
265+
"Guid": "5770385F-C22A-43E0-BF4C-06F5698FFBD9"
266+
}
267+
},
268+
"EventID": 11,
269+
"Version": 2,
270+
"Level": 4,
271+
"Task": 11,
272+
"Opcode": 0,
273+
"Keywords": "0x8000000000000000",
274+
"TimeCreated": {
275+
"#attributes": {
276+
"SystemTime": "2026-04-08T10:58:04.880098Z"
277+
}
278+
},
279+
"EventRecordID": 129830,
280+
"Correlation": null,
281+
"Execution": {
282+
"#attributes": {
283+
"ProcessID": 4584,
284+
"ThreadID": 5116
285+
}
286+
},
287+
"Channel": "Microsoft-Windows-Sysmon/Operational",
288+
"Computer": "swachchhanda",
289+
"Security": {
290+
"#attributes": {
291+
"UserID": "S-1-5-18"
292+
}
293+
}
294+
},
295+
"EventData": {
296+
"RuleName": "-",
297+
"UtcTime": "2026-04-08 10:58:04.876",
298+
"ProcessGuid": "0197231E-34BB-69D6-730F-000000000D00",
299+
"ProcessId": 12184,
300+
"Image": "C:\\Users\\xodih\\Downloads\\nxc-windows-latest\\nxc.exe",
301+
"TargetFilename": "C:\\Users\\xodih\\AppData\\Local\\Temp\\_MEI121842\\nxc\\data\\veeam_dump_module\\veeam_dump_postgresql.ps1",
302+
"CreationUtcTime": "2026-04-08 10:58:04.876",
303+
"User": "swachchhanda\\xodih"
304+
}
305+
}
306+
}
307+
{
308+
"Event": {
309+
"#attributes": {
310+
"xmlns": "http://schemas.microsoft.com/win/2004/08/events/event"
311+
},
312+
"System": {
313+
"Provider": {
314+
"#attributes": {
315+
"Name": "Microsoft-Windows-Sysmon",
316+
"Guid": "5770385F-C22A-43E0-BF4C-06F5698FFBD9"
317+
}
318+
},
319+
"EventID": 11,
320+
"Version": 2,
321+
"Level": 4,
322+
"Task": 11,
323+
"Opcode": 0,
324+
"Keywords": "0x8000000000000000",
325+
"TimeCreated": {
326+
"#attributes": {
327+
"SystemTime": "2026-04-08T10:58:04.888584Z"
328+
}
329+
},
330+
"EventRecordID": 129831,
331+
"Correlation": null,
332+
"Execution": {
333+
"#attributes": {
334+
"ProcessID": 4584,
335+
"ThreadID": 5116
336+
}
337+
},
338+
"Channel": "Microsoft-Windows-Sysmon/Operational",
339+
"Computer": "swachchhanda",
340+
"Security": {
341+
"#attributes": {
342+
"UserID": "S-1-5-18"
343+
}
344+
}
345+
},
346+
"EventData": {
347+
"RuleName": "-",
348+
"UtcTime": "2026-04-08 10:58:04.880",
349+
"ProcessGuid": "0197231E-34BB-69D6-730F-000000000D00",
350+
"ProcessId": 12184,
351+
"Image": "C:\\Users\\xodih\\Downloads\\nxc-windows-latest\\nxc.exe",
352+
"TargetFilename": "C:\\Users\\xodih\\AppData\\Local\\Temp\\_MEI121842\\nxc\\data\\wmiexec_event_vbscripts\\Exec_Command_Silent.vbs",
353+
"CreationUtcTime": "2026-04-08 10:58:04.880",
354+
"User": "swachchhanda\\xodih"
355+
}
356+
}
357+
}
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
id: 0f3349c0-c715-462e-bf26-2241a149f20e
2+
description: N/A
3+
date: 2026-04-08
4+
author: Swachchhanda Shrawan Poudel (Nextron Systems)
5+
rule_metadata:
6+
- id: efc21479-9e83-41da-8cf1-122e06ba8db3
7+
title: HackTool - NetExec File Indicators
8+
regression_tests_info:
9+
- name: Positive Detection Test
10+
type: evtx
11+
provider: Microsoft-Windows-Sysmon
12+
match_count: 7
13+
path: regression_data/rules/windows/file/file_event/file_event_win_hktl_netexec_file_indicators/efc21479-9e83-41da-8cf1-122e06ba8db3.evtx

0 commit comments

Comments
 (0)