Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0360 — Behavioral Detection of Domain Group Discovery
DET0360

Behavioral Detection of Domain Group Discovery

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN1025 Analytic 1025
Windows

Detection of domain group enumeration through command-line utilities such as 'net group /domain' or PowerShell cmdlets, followed by suspicious access to API calls or LSASS memory.

WinEventLog:Security EventCode=4688 WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106
[TimeWindow] Adjustable window to track chained discovery activity (e.g., 5-10 minutes).
[UserContext] Tune to focus on non-admin users or service accounts performing enumeration.
[ProcessLineageDepth] How far back the parent-child process chain is correlated.
AN1026 Analytic 1026
Linux

Behavioral detection of domain group enumeration via ldapsearch or custom scripts leveraging LDAP over the network.

auditd:SYSCALL execve linux:syslog sshd logs NSM:Flow ldap.log
[LDAPQueryDepth] Tunable based on number of LDAP queries before flagging suspicious behavior.
[CommandPattern] Pattern matching against common ldapsearch or shell enumeration flags.
AN1027 Analytic 1027
macOS

Enumeration of domain groups using dscacheutil or dscl commands, often following initial login or domain trust queries.

macos:unifiedlog process events
[CommandSignatureThreshold] Defines how strictly command patterns must match known enumeration syntax.
[TimeWindow] Adjustable window to correlate chained behavior such as group enumeration followed by user targeting.

Detected Techniques

1

Details

MITRE ID
DET0360
STIX ID
x-mitre-detection-strategy--69f22425-2ebb-4f3c-ab4d-fb9c6645f2f7
Analytics
3
Techniques Detected
1
By Tactic
Discovery
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.