Zerologon Exploitation Using Well-known Tools — Detection Rule

This rule is designed to detect attempts to exploit Zerologon (CVE-2020-1472) vulnerability using mimikatz zerologon module or other exploits from machine with "kali" hostname.

Read the full analysis on IntelFusions