Elastic low stable eql
Enumeration of Administrator Accounts
Identifies instances of lower privilege accounts enumerating Administrator accounts or groups using built-in Windows tools.
Detection Logic
process where host.os.type == "windows" and event.type == "start" and
(
(
(
(process.name : "net.exe" or ?process.pe.original_file_name == "net.exe") or
((process.name : "net1.exe" or ?process.pe.original_file_name == "net1.exe") and not process.parent.name : "net.exe")
) and
process.args : ("group", "user", "localgroup") and
process.args : ("*admin*", "Domain Admins", "Remote Desktop Users", "Enterprise Admins", "Organization Management")
and not process.args : ("/add", "/delete")
) or
(
(process.name : "wmic.exe" or ?process.pe.original_file_name == "wmic.exe") and
process.args : ("group", "useraccount")
)
) and not user.id : ("S-1-5-18", "S-1-5-19", "S-1-5-20") Field Validations
Loading…
Comments (0)
Loading comments...