""ET POLICY Possible winexe over SMB - Possible Lateral Movement""

SID: 2026879

Revision: 3

Class Type: bad-unknown

Metadata: affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2019_02_05, deployment Perimeter, performance_impact Moderate, signature_severity Informational, updated_at 2020_11_10, reviewed_at 2024_05_06, mitre_tactic_id TA0008, mitre_tactic_name Lateral_Movement, mitre_technique_id T1570, mitre_technique_name Lateral_Tool_Transfer

Reference:

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: $HOME_NET

Destination Port: [139,445]

Flow: to_server,established

Contents:

  • Value: "|ff|SMB" Depth: 4 Offset: 4

  • Value: "|5c 00|a|00|h|00|e|00|x|00|e|00|c|00 00 00|"

Within:

PCRE:

Special Options:

  • fast_pattern

  • nocase

source