Sagan unknown stable other

[WINDOWS-SECURITY] Possible Active Directory Computer Enumeration (READ)

[WINDOWS-SECURITY] Possible Active Directory Computer Enumeration (READ)

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SECURITY] Possible Active Directory Computer Enumeration (READ)"; program:*Security*; event_id:4662; json_map:"username",".SubjectUserName"; json_map:"event_id",".EventID"; json_map:"message",".Message"; normalize; content:!"$ Account Domain
| 3a
| "; content:"Object Type
| 3a 20 25 7b
| bf967a86-0de6-11d0-a285-00aa003049e2
| 7d
| "; content:"READ"; nocase; json_map: "src_ip", ".xff"; after:track by_src&by_username, count 200, seconds 60; threshold:type suppress, track by_src&by_username, count 1, seconds 86400; classtype:discovery; priority:1; reference:url,https://medium.com/securonix-tech-blog/detecting-ldap-enumeration-and-bloodhound-s-sharphound-collector-using-active-directory-decoys-dfc840f2f644; reference:url,http://www.selfadsi.org/deep-inside/ad-security-descriptors.htm; sid:5014579; rev:2; metadata:deployment Endpoint,affected_product NONE,affected_version NONE,mitigation NONE,deprecation_reason NONE,tag NONE, created_at 2024_04_16, updated_at 2025_05_12, mitre_tactic_id TA0007, mitre_technique_id T1018;)

Field Validations

Loading…

Comments (0)

Loading comments...