Elastic medium stable eql
Windows Network Enumeration
Identifies attempts to enumerate hosts in a network using the built-in Windows net.exe tool.
Detection Logic
process where host.os.type == "windows" and event.type == "start" and
((process.name : "net.exe" or process.pe.original_file_name == "net.exe") or
((process.name : "net1.exe" or process.pe.original_file_name == "net1.exe") and
not process.parent.name : "net.exe")) and
(process.args : "view" or (process.args : "time" and process.args : "\\\\*")) and
not process.command_line : "net view \\\\localhost "
/* expand when ancestry is available
and not descendant of [process where event.type == "start" and process.name : "cmd.exe" and
((process.parent.name : "userinit.exe") or
(process.parent.name : "gpscript.exe") or
(process.parent.name : "explorer.exe" and
process.args : "C:\\*\\Start Menu\\Programs\\Startup\\*.bat*"))]
*/ Field Validations
Loading…
Comments (0)
Loading comments...