Search and filter across all detection sources
788 rules
[ONELOGIN] NO_ACTIVE_ACTIVE_DIRECTORY_CONNECTORS
Azure Eventhub Active Directory detected
[NETWRIX] Active Directory User Added
[NETWRIX] Active Directory Security Group Added
Potential Active Directory Reconnaissance/Enumeration Via LDAP
Detects potential Active Directory enumeration via LDAP
[WINDOWS-SECURITY] Possible Active Directory User Enumeration (READ)
[EXTRAHOP] Web Directory Scan
[WINDOWS-SECURITY] Possible Active Directory Computer Enumeration (READ)
[WINDOWS-SECURITY] Possible Active Directory Groups Enumeration (READ)
[WINDOWS-SECURITY] Possible Active Directory OU Enumeration (READ)
Alsid Active Directory attacks pathways
'Searches for triggered Indicators of Exposures related to Active Directory attacks pathways'
TIE Active Directory attacks pathways
'Searches for triggered Indicators of Exposures related to Active Directory attacks pathways.'
[EXTRAHOP] CVE-2022-26923 Active Directory Domain Services Exploit Attempt
[NETWRIX] Active Directory Computer Modified Encryption Type: 0x17
[NETWRIX] Active Directory Member Added to Security Group
Tenable.ad Active Directory attacks pathways
Active Directory Group Enumeration With Get-AdGroup
Detects usage of the "Get-AdGroup" cmdlet to enumerate Groups within Active Directory
Active Directory Computers Enumeration With Get-AdComputer
Detects usage of the "Get-AdComputer" to enumerate Computers or properties within Active Directory.
Active Directory Structure Export Via Csvde.EXE
Detects the execution of "csvde.exe" in order to export organizational Active Directory structure.
Active Directory Structure Export Via Ldifde.EXE
Detects the execution of "ldifde.exe" in order to export organizational Active Directory structure.