title: HackTool - KrbRelayUp Execution id: 12827a56-61a4-476a-a9cb-f3068f191073 status: test description: Detects KrbRelayUp used to perform a universal no-fix local privilege escalation in Windows domain environments where LDAP signing is not enforced references: - https://github.com/Dec0ne/KrbRelayUp author: Florian Roth (Nextron Systems) date: 2022-04-26 modified: 2023-02-04 tags: - attack.credential-access - attack.t1558.003 - attack.lateral-movement - attack.t1550.003 logsource: category: process_creation product: windows detection: selection_img: - Image|endswith: '\KrbRelayUp.exe' - OriginalFileName: 'KrbRelayUp.exe' # In case the file has been renamed after compilation selection_cli_1: CommandLine|contains|all: - ' relay ' - ' -Domain ' - ' -ComputerName ' selection_cli_2: CommandLine|contains|all: - ' krbscm ' - ' -sc ' selection_cli_3: CommandLine|contains|all: - ' spawn ' - ' -d ' - ' -cn ' - ' -cp ' condition: 1 of selection_* falsepositives: - Unlikely level: high