Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

Siemphony’s repertoire

Existing account altered to weaken or extend its credentials

AN0265 asks for account attribute changes correlated with unusual process lineage or timing. The correlation half is not expressible — its TimeWindow knob wants a five-minute join between a suspicious process and a directory change, and its SubjectTargetMismatch knob wants the modifying account compared against the modified one, and lib/sigma has no timeframe, no aggregation and no field-to-field comparison. So this rule takes the analytic's process-creation leg alone and keeps it at the parent technique: it matches the commands that alter an account that already exists in ways that preserve or broaden an adversary's hold on it — clearing the password requirement, lifting expiry, re-enabling a dormant account, resetting a password, or bolting a service principal name onto a user so it becomes Kerberoastable. The two account-control flags that matter most here, PasswordNeverExpires and DoesNotRequirePreAuth, are matched only when a setting cmdlet appears on the same command line, because those two words are far more often typed in a `Get-ADUser -Filter`/`-Properties` audit query — an enumeration that belongs to T1087, not here — than in an actual write. Group membership changes are deliberately excluded even though the analytic's other log source lists EventID 4728, because adding an account to a local or domain group is T1098.007 and belongs in that brief, not under the parent tag. Two limits worth stating before deployment. The brief sources this leg from Sysmon EventID 1, which records CommandLine natively; if the site feeds Security EventID 4688 into the same `process_creation` category instead, *Audit Process Creation* and the separate *Include command line in process creation events* policy must both be enabled or every term below is blind and the rule returns zero rows that read as quiet rather than deaf. And because this is process-creation only, a cmdlet invoked inside a .ps1 body, from a DLL, or over LDAP by a compiled tool leaves nothing here — the directory-side events would, but this rule is not written in their vocabulary. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0096, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full description

The detection

The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.

detection.yml

title: Existing account altered to weaken or extend its credentialsid: 872128ce-b6a8-43b5-9def-42af76055405status: experimentaldescription: |  AN0265 asks for account attribute changes correlated with unusual process  lineage or timing. The correlation half is not expressible — its TimeWindow  knob wants a five-minute join between a suspicious process and a directory  change, and its SubjectTargetMismatch knob wants the modifying account  compared against the modified one, and lib/sigma has no timeframe, no  aggregation and no field-to-field comparison. So this rule takes the analytic's  process-creation leg alone and keeps it at the parent technique: it matches the  commands that alter an account that already exists in ways that preserve or  broaden an adversary's hold on it — clearing the password requirement, lifting  expiry, re-enabling a dormant account, resetting a password, or bolting a  service principal name onto a user so it becomes Kerberoastable. The two  account-control flags that matter most here, PasswordNeverExpires and  DoesNotRequirePreAuth, are matched only when a setting cmdlet appears on the  same command line, because those two words are far more often typed in a  `Get-ADUser -Filter`/`-Properties` audit query — an enumeration that belongs  to T1087, not here — than in an actual write. Group  membership changes are deliberately excluded even though the analytic's other  log source lists EventID 4728, because adding an account to a local or domain  group is T1098.007 and belongs in that brief, not under the parent tag. Two  limits worth stating before deployment. The brief sources this leg from Sysmon  EventID 1, which records CommandLine natively; if the site feeds Security  EventID 4688 into the same `process_creation` category instead, *Audit Process  Creation* and the separate *Include command line in process creation events*  policy must both be enabled or every term below is blind and the rule returns  zero rows that read as quiet rather than deaf. And because this is  process-creation only, a cmdlet invoked inside a .ps1 body, from a DLL, or over  LDAP by a compiled tool leaves nothing here — the directory-side events would,  but this rule is not written in their vocabulary.  UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0096, not hand-written and not tested by its author. Any lab result is on this rule's own page.references:  - https://attack.mitre.org/techniques/T1098  - https://attack.mitre.org/detectionstrategies/DET0096author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags:  - attack.persistence  - attack.privilege-escalation  - attack.t1098logsource:  category: process_creation  product: windowsdetection:  selection_net_tool:    Image|endswith:      - '\net.exe'      - '\net1.exe'    CommandLine|contains: ' user '  selection_net_switch:    CommandLine|contains:      - '/active:yes'      - '/expires:never'      - '/passwordreq:no'      - '/passwordchg:no'      - '/logonpasswordchg:no'      - '/times:all'  selection_cmdlet:    CommandLine|contains:      - 'Set-ADAccountPassword'      - 'Set-ADAccountControl'      - 'Set-LocalUser'      - 'Enable-LocalUser'      - 'Enable-ADAccount'  selection_attr_flag:    CommandLine|contains:      - 'PasswordNeverExpires'      - 'DoesNotRequirePreAuth'      - 'AllowReversiblePasswordEncryption'  selection_attr_write:    CommandLine|contains:      - 'Set-ADUser'      - 'Set-ADAccountControl'      - 'Set-LocalUser'  selection_spn_tool:    Image|endswith: '\setspn.exe'    CommandLine|contains:      - ' -a '      - ' -s '  condition: (selection_net_tool and selection_net_switch) or selection_cmdlet or (selection_attr_flag and selection_attr_write) or selection_spn_toolfalsepositives:  - "Identity operations run from a management host. Password resets and account re-enablement are the two most common helpdesk actions in any organisation, and joiner-mover-leaver automation performs them in bulk on a schedule, so Set-ADAccountPassword and Enable-ADAccount alone can produce dozens to hundreds of matches a day from a handful of admin workstations and IAM connectors. That volume is why this rule is scored low; scope it to accounts and hosts outside the identity team before raising it."  - "Service-account provisioning during application installs. SQL Server, Exchange, SharePoint and most Kerberos-authenticating products register a service principal name with setspn -s and set PasswordNeverExpires on the account they run as, as a documented and required install step."  - "Local administrator and break-glass password rotation. Scripted rotation tooling calls Set-LocalUser -Password on every host on a fixed cycle, which matches the cmdlet selection on the entire fleet at once."  - "Image build and lab provisioning. Golden-image and test-rig scripts commonly run net user Administrator /active:yes or set /expires:never on a local account so that unattended setup can proceed, tripping the net.exe selection on every machine built."level: low

Sentinel · KQL

Run this as a search.

DeviceProcessEvents| where ((((((FolderPath endswith "\\net.exe" or FolderPath endswith "\\net1.exe") and ProcessCommandLine contains " user ") and (ProcessCommandLine contains "/active:yes" or ProcessCommandLine contains "/expires:never" or ProcessCommandLine contains "/passwordreq:no" or ProcessCommandLine contains "/passwordchg:no" or ProcessCommandLine contains "/logonpasswordchg:no" or ProcessCommandLine contains "/times:all")) or (ProcessCommandLine contains "Set-ADAccountPassword" or ProcessCommandLine contains "Set-ADAccountControl" or ProcessCommandLine contains "Set-LocalUser" or ProcessCommandLine contains "Enable-LocalUser" or ProcessCommandLine contains "Enable-ADAccount")) or ((ProcessCommandLine contains "PasswordNeverExpires" or ProcessCommandLine contains "DoesNotRequirePreAuth" or ProcessCommandLine contains "AllowReversiblePasswordEncryption") and (ProcessCommandLine contains "Set-ADUser" or ProcessCommandLine contains "Set-ADAccountControl" or ProcessCommandLine contains "Set-LocalUser"))) or (FolderPath endswith "\\setspn.exe" and (ProcessCommandLine contains " -a " or ProcessCommandLine contains " -s ")))

Splunk · SPL

Run this as a search.

index=* ((((((Image="*\\net.exe" OR Image="*\\net1.exe") AND CommandLine="* user *") AND (CommandLine="*/active:yes*" OR CommandLine="*/expires:never*" OR CommandLine="*/passwordreq:no*" OR CommandLine="*/passwordchg:no*" OR CommandLine="*/logonpasswordchg:no*" OR CommandLine="*/times:all*")) OR (CommandLine="*Set-ADAccountPassword*" OR CommandLine="*Set-ADAccountControl*" OR CommandLine="*Set-LocalUser*" OR CommandLine="*Enable-LocalUser*" OR CommandLine="*Enable-ADAccount*")) OR ((CommandLine="*PasswordNeverExpires*" OR CommandLine="*DoesNotRequirePreAuth*" OR CommandLine="*AllowReversiblePasswordEncryption*") AND (CommandLine="*Set-ADUser*" OR CommandLine="*Set-ADAccountControl*" OR CommandLine="*Set-LocalUser*"))) OR (Image="*\\setspn.exe" AND (CommandLine="* -a *" OR CommandLine="* -s *")))

Elastic · ES|QL

Run this as a search.

FROM logs-*| WHERE ((((((TO_LOWER(process.executable) LIKE "*\\\\net.exe" OR TO_LOWER(process.executable) LIKE "*\\\\net1.exe") AND TO_LOWER(process.command_line) LIKE "* user *") AND (TO_LOWER(process.command_line) LIKE "*/active:yes*" OR TO_LOWER(process.command_line) LIKE "*/expires:never*" OR TO_LOWER(process.command_line) LIKE "*/passwordreq:no*" OR TO_LOWER(process.command_line) LIKE "*/passwordchg:no*" OR TO_LOWER(process.command_line) LIKE "*/logonpasswordchg:no*" OR TO_LOWER(process.command_line) LIKE "*/times:all*")) OR (TO_LOWER(process.command_line) LIKE "*set-adaccountpassword*" OR TO_LOWER(process.command_line) LIKE "*set-adaccountcontrol*" OR TO_LOWER(process.command_line) LIKE "*set-localuser*" OR TO_LOWER(process.command_line) LIKE "*enable-localuser*" OR TO_LOWER(process.command_line) LIKE "*enable-adaccount*")) OR ((TO_LOWER(process.command_line) LIKE "*passwordneverexpires*" OR TO_LOWER(process.command_line) LIKE "*doesnotrequirepreauth*" OR TO_LOWER(process.command_line) LIKE "*allowreversiblepasswordencryption*") AND (TO_LOWER(process.command_line) LIKE "*set-aduser*" OR TO_LOWER(process.command_line) LIKE "*set-adaccountcontrol*" OR TO_LOWER(process.command_line) LIKE "*set-localuser*"))) OR (TO_LOWER(process.executable) LIKE "*\\\\setspn.exe" AND (TO_LOWER(process.command_line) LIKE "* -a *" OR TO_LOWER(process.command_line) LIKE "* -s *")))

Wazuh · XML rule

Deploy to your manager — this is a rule, not a search.

<group name="sigma,windows,process_creation,">  <!-- Rule ids must be unique on your manager; 100000+ is the user range. -->  <!-- 4 rules: the Sigma condition ORs across different fields,       which one rule cannot express. Any one matching is a hit. -->  <rule id="100000" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="Image" type="pcre2">(?i)(\\net\.exe$|\\net1\.exe$)</field>    <field name="CommandLine" type="pcre2">(?i) user </field>    <field name="CommandLine" type="pcre2">(?i)(/active:yes|/expires:never|/passwordreq:no|/passwordchg:no|/logonpasswordchg:no|/times:all)</field>    <description>Existing account altered to weaken or extend its credentials (1/4)</description>    <mitre>      <id>T1098</id>    </mitre>  </rule>   <rule id="100001" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="CommandLine" type="pcre2">(?i)(Set-ADAccountPassword|Set-ADAccountControl|Set-LocalUser|Enable-LocalUser|Enable-ADAccount)</field>    <description>Existing account altered to weaken or extend its credentials (2/4)</description>    <mitre>      <id>T1098</id>    </mitre>  </rule>   <rule id="100002" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="CommandLine" type="pcre2">(?i)(PasswordNeverExpires|DoesNotRequirePreAuth|AllowReversiblePasswordEncryption)</field>    <field name="CommandLine" type="pcre2">(?i)(Set-ADUser|Set-ADAccountControl|Set-LocalUser)</field>    <description>Existing account altered to weaken or extend its credentials (3/4)</description>    <mitre>      <id>T1098</id>    </mitre>  </rule>   <rule id="100003" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="Image" type="pcre2">(?i)\\setspn\.exe$</field>    <field name="CommandLine" type="pcre2">(?i)( -a | -s )</field>    <description>Existing account altered to weaken or extend its credentials (4/4)</description>    <mitre>      <id>T1098</id>    </mitre>  </rule></group>

Verdicts · reactions · comments

Community

Verdicts from engineers who actually deployed it, and the conversation around it.

Log in to react
Not yet reported on

Nobody has run this in a real environment and said what happened.

Verdicts from engineers who deployed it

0 cast

No verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.

Log in to report a verdict.

Log in to join the discussion.

No comments yet. Someone who deploys this will have something to say about it.