Sagan critical stable other

[WINDOWS-SECURITY] Possible Active Directory User Enumeration (READ)

[WINDOWS-SECURITY] Possible Active Directory User Enumeration (READ)

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SECURITY] Possible Active Directory User Enumeration (READ)"; program:*Security*; event_id:4662; json_map:"username",".SubjectUserName"; json_map:"event_id",".EventID"; json_map:"message",".Message"; normalize; content:!"$ Account Domain
| 3a
| "; content:"Object Type
| 3a 20 25 7b
| bf967aba-0de6-11d0-a285-00aa003049e2
| 7d
| "; content:"Accesses
| 3a 20
| Read Property"; nocase; after:track by_username, count 200, seconds 60; threshold:type suppress, track by_username, count 1, seconds 86400; classtype:trojan-activity; reference:url,https://medium.com/securonix-tech-blog/detecting-ldap-enumeration-and-bloodhound-s-sharphound-collector-using-active-directory-decoys-dfc840f2f644; reference:url,http://www.selfadsi.org/deep-inside/ad-security-descriptors.htm; sid:5014577; rev:1; metadata:deployment Endpoint,affected_product NONE,affected_version NONE,mitigation NONE,deprecation_reason NONE,tag NONE, created_at 2024_04_16, updated_at 2024_04_16, mitre_tactic_id TA0007, mitre_technique_id T1018;)

Field Validations

Loading…

Comments (0)

Loading comments...