Possible Impacket SecretDump Remote Activity - Zeek — Detection Rule

Detect AD credential dumping using impacket secretdump HKTL. Based on the SIGMA rules/windows/builtin/win_impacket_secretdump.yml

Read the full analysis on IntelFusions