title: Outbound Network Connection To Public IP Via Winlogon id: 7610a4ea-c06d-495f-a2ac-0a696abcfd3b status: test description: Detects a "winlogon.exe" process that initiate network communications with public IP addresses references: - https://www.microsoft.com/en-us/security/blog/2023/04/11/guidance-for-investigating-attacks-using-cve-2022-21894-the-blacklotus-campaign/ author: Christopher Peacock @securepeacock, SCYTHE @scythe_io date: 2023-04-28 modified: 2024-03-12 tags: - attack.execution - attack.command-and-control - attack.stealth - attack.t1218.011 logsource: category: network_connection product: windows detection: selection: Image|endswith: '\winlogon.exe' Initiated: 'true' filter_main_local_ranges: DestinationIp|cidr: - '127.0.0.0/8' - '10.0.0.0/8' - '172.16.0.0/12' - '192.168.0.0/16' - '169.254.0.0/16' - '::1/128' # IPv6 loopback - 'fe80::/10' # IPv6 link-local addresses - 'fc00::/7' # IPv6 private addresses condition: selection and not 1 of filter_main_* falsepositives: - Communication to other corporate systems that use IP addresses from public address spaces level: medium