{"id":"T1087","name":"Account Discovery","url":"https://attack.mitre.org/techniques/T1087","tactics":["discovery"],"platforms":["ESXi","IaaS","Identity Provider","Linux","macOS","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0587","stix_id":"x-mitre-detection-strategy--fdda430c-e4f6-43ce-95d6-0f97253ff6a2","name":"Enumeration of User or Account Information Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0587","analytics":[{"id":"AN1612","stix_id":"x-mitre-analytic--e576eaeb-2158-40f9-8edb-c119eac56442","name":"Analytic 1612","description":"Detection of processes performing local or domain account enumeration by invoking account directory queries or security APIs followed by structured output of account lists. The defender observes command execution or API invocation patterns that retrieve account information and produce enumeration artifacts shortly afterward.","url":"https://attack.mitre.org/detectionstrategies/DET0587#AN1612","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4798, 4799","data_component":"DC0099","data_component_name":"Group Enumeration","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"CommandLinePattern","description":"Match variations in enumeration commands like 'net user', 'Get-ADUser', 'dsquery'."},{"field":"TimeWindow","description":"Short burst of account enumeration commands may indicate automation."},{"field":"UserContext","description":"Restrict to non-admin accounts or unexpected users executing enumeration commands."}],"live":true,"detection_strategies":["DET0587"],"techniques":["T1087"]},{"id":"AN1613","stix_id":"x-mitre-analytic--7b0d80c0-807e-46b1-b3f7-fd3e4f3aceba","name":"Analytic 1613","description":"Enumeration of users and groups through suspicious shell commands or unauthorized access to /etc/passwd or /etc/shadow.","url":"https://attack.mitre.org/detectionstrategies/DET0587#AN1613","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"PATH","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"linux:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"linux-sysmon"}],"mutable_elements":[{"field":"AccessedFile","description":"Tune based on file paths such as '/etc/passwd', '/etc/group', '/etc/shadow'."},{"field":"ParentProcessName","description":"Filter known admin processes to reduce false positives."}],"live":true,"detection_strategies":["DET0587"],"techniques":["T1087"]},{"id":"AN1614","stix_id":"x-mitre-analytic--24aa5ee9-ba7f-4991-b32a-27d40ee2d010","name":"Analytic 1614","description":"Detection of account enumeration through directory service queries or system utilities accessing account metadata stores, followed by structured enumeration output.","url":"https://attack.mitre.org/detectionstrategies/DET0587#AN1614","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process event","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"DirectoryService queries retrieving account information","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"CommandLine","description":"Tune for dscl -list, dscacheutil -q user, id -un, etc."},{"field":"ExecutionContext","description":"Alert if enumeration is performed in non-console session or by unusual users."}],"live":true,"detection_strategies":["DET0587"],"techniques":["T1087"]},{"id":"AN1615","stix_id":"x-mitre-analytic--5d7158ce-17f5-4643-bde2-c0a4f2ba0b73","name":"Analytic 1615","description":"Detection of enumeration of identity entities through cloud provider APIs where principals retrieve account metadata such as IAM users or roles in rapid succession.","url":"https://attack.mitre.org/detectionstrategies/DET0587#AN1615","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"DescribeUsers / ListUsers / GetUser","data_component":"DC0083","data_component_name":"Cloud Service Enumeration","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"API_Method","description":"Tune based on which IAM APIs are used and their frequency."},{"field":"CallerType","description":"Differentiate user-initiated from automated/scripted enumeration."}],"live":true,"detection_strategies":["DET0587"],"techniques":["T1087"]},{"id":"AN1616","stix_id":"x-mitre-analytic--cb177f89-c8a4-4233-a2e4-3fdd02dccba1","name":"Analytic 1616","description":"Detection of identity directory enumeration through API calls or administrative queries retrieving multiple account objects within a short interval.","url":"https://attack.mitre.org/detectionstrategies/DET0587#AN1616","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:signinlogs","channel":"Graph API Query","data_component":"DC0083","data_component_name":"Cloud Service Enumeration","log_source_slug":"azure-signinlogs"},{"name":"saas:okta","channel":"User Enumeration Events","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"saas-okta"}],"mutable_elements":[{"field":"QueryType","description":"Detect user vs role enumeration. Tune based on query scope."},{"field":"AppContext","description":"Correlate enumeration with unexpected app registrations or identities."}],"live":true,"detection_strategies":["DET0587"],"techniques":["T1087"]},{"id":"AN1617","stix_id":"x-mitre-analytic--c4973f27-c8db-4478-aaf8-eb73580fceec","name":"Analytic 1617","description":"Detection of enumeration activity when system processes query ESXi host account configuration or management APIs to retrieve user account listings.","url":"https://attack.mitre.org/detectionstrategies/DET0587#AN1617","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vpxd","channel":"vCenter Management","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-vpxd"}],"mutable_elements":[{"field":"CommandPattern","description":"Tune based on known enumeration commands: 'vim-cmd vimsvc/auth/userlist'."},{"field":"PrivilegedSession","description":"Elevated enumeration from vpxuser or root may indicate threat activity."}],"live":true,"detection_strategies":["DET0587"],"techniques":["T1087"]},{"id":"AN1618","stix_id":"x-mitre-analytic--d85db7b4-5eb1-4781-b92c-a18102a568dc","name":"Analytic 1618","description":"Account enumeration via bulk access to user directory features or hidden APIs.","url":"https://attack.mitre.org/detectionstrategies/DET0587#AN1618","platforms":["SaaS"],"log_source_references":[{"name":"gcp:audit","channel":"Directory API Access","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"gcp-audit"}],"mutable_elements":[{"field":"EndpointURL","description":"Tune based on enumeration from directory endpoints such as /users, /groups."},{"field":"UserAgent","description":"Detect scripted enumeration via curl/wget or unknown tools."}],"live":true,"detection_strategies":["DET0587"],"techniques":["T1087"]},{"id":"AN1619","stix_id":"x-mitre-analytic--06e0501e-a87e-452d-9ab5-93ed9a5eade5","name":"Analytic 1619","description":"Account discovery via VBA macros, COM objects, or embedded scripting.","url":"https://attack.mitre.org/detectionstrategies/DET0587#AN1619","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Scripted Activity","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"MacroName","description":"Alert on auto-running macros accessing directory or user info."},{"field":"ExecutionScope","description":"Focus on macros invoking LDAP, ADODB, or WMI queries."}],"live":true,"detection_strategies":["DET0587"],"techniques":["T1087"]}],"live":true,"version":"1.0","techniques":["T1087"]}],"sigma_rules":[{"id":"02030f2f-6199-49ec-b258-ea71b07e03dc","title":"Malicious PowerShell Commandlets - ProcessCreation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-02","modified":"2025-12-10","description":"Detects Commandlet names from well-known PowerShell exploitation frameworks","references":["https://adsecurity.org/?p=2921","https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries","https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1","https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1","https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1","https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1","https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/","https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/","https://github.com/calebstewart/CVE-2021-1675","https://github.com/BloodHoundAD/BloodHound/blob/0927441f67161cc6dc08a53c63ceb8e333f55874/Collectors/AzureHound.ps1","https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html","https://github.com/HarmJ0y/DAMP","https://github.com/samratashok/nishang","https://github.com/DarkCoderSc/PowerRunAsSystem/","https://github.com/besimorhino/powercat","https://github.com/Kevin-Robertson/Powermad","https://github.com/adrecon/ADRecon","https://github.com/adrecon/AzureADRecon","https://github.com/sadshade/veeam-creds/blob/6010eaf31ba41011b58d6af3950cffbf6f5cea32/Veeam-Get-Creds.ps1","https://github.com/The-Viper-One/Invoke-PowerDPAPI/","https://github.com/Arno0x/DNSExfiltrator/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.discovery","attack.t1482","attack.t1087","attack.t1087.001","attack.t1087.002","attack.t1069.001","attack.t1069.002","attack.t1069","attack.t1059.001"],"path":"rules/windows/process_creation/proc_creation_win_powershell_malicious_cmdlets.yml","techniques":["T1482","T1087","T1087.001","T1087.002","T1069.001","T1069.002","T1069","T1059.001"],"cves":[]},{"id":"24549159-ac1b-479c-8175-d42aea947cae","title":"Hacktool Ruler","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-05-31","modified":"2022-10-09","description":"This events that are generated when using the hacktool Ruler by Sensepost","references":["https://github.com/sensepost/ruler","https://github.com/sensepost/ruler/issues/47","https://github.com/staaldraad/go-ntlm/blob/cd032d41aa8ce5751c07cb7945400c0f5c81e2eb/ntlm/ntlmv1.go#L427","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4776","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4624"],"logsource":{"product":"windows","service":"security"},"tags":["attack.discovery","attack.execution","attack.collection","attack.lateral-movement","attack.t1087","attack.t1114","attack.t1059","attack.t1550.002"],"path":"rules/windows/builtin/security/win_security_alert_ruler.yml","techniques":["T1087","T1114","T1059","T1550.002"],"cves":[]},{"id":"38646daa-e78f-4ace-9de0-55547b2d30da","title":"PUA - Seatbelt Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-10-18","modified":"2023-02-04","description":"Detects the execution of the PUA/Recon tool Seatbelt via PE information of command line parameters","references":["https://github.com/GhostPack/Seatbelt","https://www.bluetangle.dev/2022/08/fastening-seatbelt-on-threat-hunting.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1526","attack.t1087","attack.t1083"],"path":"rules/windows/process_creation/proc_creation_win_pua_seatbelt.yml","techniques":["T1526","T1087","T1083"],"cves":[]},{"id":"4ebc877f-4612-45cb-b3a5-8e3834db36c9","title":"Webshell Hacking Activity Patterns","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-03-17","modified":"2023-11-09","description":"Detects certain parent child patterns found in cases in which a web shell is used to perform certain credential dumping or exfiltration activities on a compromised system\n","references":["https://youtu.be/7aemGhaE9ds?t=641"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.discovery","attack.t1505.003","attack.t1018","attack.t1033","attack.t1087"],"path":"rules/windows/process_creation/proc_creation_win_webshell_hacking.yml","techniques":["T1505.003","T1018","T1033","T1087"],"cves":[]},{"id":"65f77b1e-8e79-45bf-bb67-5988a8ce45a5","title":"SharpHound Recon Account Discovery","author":"Sagie Dulce, Dekel Paz","status":"test","level":"high","date":"2022-01-01","modified":null,"description":"Detects remote RPC calls useb by SharpHound to map remote connections and local group membership.","references":["https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-wkst/55118c55-2122-4ef9-8664-0c1ff9e168f3","https://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-WKST.md","https://github.com/zeronetworks/rpcfirewall","https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/"],"logsource":{"product":"rpc_firewall","category":"application"},"tags":["attack.t1087","attack.discovery"],"path":"rules/application/rpc_firewall/rpc_firewall_sharphound_recon_account.yml","techniques":["T1087"],"cves":[]},{"id":"698d4431-514f-4c82-af4d-cf573872a9f5","title":"Potential Pikabot Discovery Activity","author":"Andreas Braathen (mnemonic.io)","status":"test","level":"high","date":"2023-10-27","modified":"2024-01-26","description":"Detects system discovery activity carried out by Pikabot, such as incl. network, user info and domain groups.\nThe malware Pikabot has been seen to use this technique as part of its C2-botnet registration with a short collection time frame (less than 1 minute).\n","references":["https://www.virustotal.com/gui/file/72f1a5476a845ea02344c9b7edecfe399f64b52409229edaf856fcb9535e3242","https://tria.ge/231023-lpw85she57/behavioral2"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1016","attack.t1049","attack.t1087","detection.emerging-threats"],"path":"rules-emerging-threats/2023/Malware/Pikabot/proc_creation_win_malware_pikabot_discovery.yml","techniques":["T1016","T1049","T1087"],"cves":[]},{"id":"7d0d0329-0ef1-4e84-a9f5-49500f9d7c6c","title":"Malicious PowerShell Commandlets - PoshModule","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-20","modified":"2025-12-10","description":"Detects Commandlet names from well-known PowerShell exploitation frameworks","references":["https://adsecurity.org/?p=2921","https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries","https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1","https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1","https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1","https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1","https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/","https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/","https://github.com/calebstewart/CVE-2021-1675","https://github.com/BloodHoundAD/BloodHound/blob/0927441f67161cc6dc08a53c63ceb8e333f55874/Collectors/AzureHound.ps1","https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html","https://github.com/HarmJ0y/DAMP","https://github.com/samratashok/nishang","https://github.com/DarkCoderSc/PowerRunAsSystem/","https://github.com/besimorhino/powercat","https://github.com/Kevin-Robertson/Powermad","https://github.com/adrecon/ADRecon","https://github.com/adrecon/AzureADRecon","https://github.com/sadshade/veeam-creds/blob/6010eaf31ba41011b58d6af3950cffbf6f5cea32/Veeam-Get-Creds.ps1","https://github.com/The-Viper-One/Invoke-PowerDPAPI/","https://github.com/Arno0x/DNSExfiltrator/"],"logsource":{"product":"windows","category":"ps_module"},"tags":["attack.execution","attack.discovery","attack.t1482","attack.t1087","attack.t1087.001","attack.t1087.002","attack.t1069.001","attack.t1069.002","attack.t1069","attack.t1059.001"],"path":"rules/windows/powershell/powershell_module/posh_pm_malicious_commandlets.yml","techniques":["T1482","T1087","T1087.001","T1087.002","T1069.001","T1069.002","T1069","T1059.001"],"cves":[]},{"id":"89819aa4-bbd6-46bc-88ec-c7f7fe30efa6","title":"Malicious PowerShell Commandlets - ScriptBlock","author":"Sean Metcalf, Florian Roth, Bartlomiej Czyz @bczyz1, oscd.community, Nasreddine Bencherchali, Tim Shelton, Mustafa Kaan Demir, Georg Lauenstein, Max Altgelt, Tobias Michalski, Austin Songer","status":"test","level":"high","date":"2017-03-05","modified":"2025-12-10","description":"Detects Commandlet names from well-known PowerShell exploitation frameworks","references":["https://adsecurity.org/?p=2921","https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries","https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1","https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1","https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1","https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1","https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/","https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/","https://github.com/calebstewart/CVE-2021-1675","https://github.com/BloodHoundAD/BloodHound/blob/0927441f67161cc6dc08a53c63ceb8e333f55874/Collectors/AzureHound.ps1","https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html","https://github.com/HarmJ0y/DAMP","https://github.com/samratashok/nishang","https://github.com/DarkCoderSc/PowerRunAsSystem/","https://github.com/besimorhino/powercat","https://github.com/Kevin-Robertson/Powermad","https://github.com/adrecon/ADRecon","https://github.com/adrecon/AzureADRecon","https://github.com/The-Viper-One/Invoke-PowerDPAPI/","https://github.com/Arno0x/DNSExfiltrator/"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.execution","attack.discovery","attack.t1482","attack.t1087","attack.t1087.001","attack.t1087.002","attack.t1069.001","attack.t1069.002","attack.t1069","attack.t1059.001"],"path":"rules/windows/powershell/powershell_script/posh_ps_malicious_commandlets.yml","techniques":["T1482","T1087","T1087.001","T1087.002","T1069.001","T1069.002","T1069","T1059.001"],"cves":[]},{"id":"98b53e78-ebaf-46f8-be06-421aafd176d9","title":"HackTool - winPEAS Execution","author":"Georg Lauenstein (sure[secure])","status":"test","level":"high","date":"2022-09-19","modified":"2023-03-23","description":"WinPEAS is a script that search for possible paths to escalate privileges on Windows hosts. The checks are explained on book.hacktricks.xyz","references":["https://github.com/carlospolop/PEASS-ng","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.discovery","attack.t1082","attack.t1087","attack.t1046"],"path":"rules/windows/process_creation/proc_creation_win_hktl_winpeas.yml","techniques":["T1082","T1087","T1046"],"cves":[]},{"id":"aae1243f-d8af-40d8-ab20-33fc6d0c55bc","title":"Suspicious Use of PsLogList","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2021-12-18","modified":"2026-06-29","description":"Detects usage of the PsLogList utility to dump event log in order to extract admin accounts and perform account discovery or delete events logs","references":["https://research.nccgroup.com/2021/01/12/abusing-cloud-services-to-fly-under-the-radar/","https://www.cybereason.com/blog/deadringer-exposing-chinese-threat-actors-targeting-major-telcos","https://github.com/3CORESec/MAL-CL/tree/master/Descriptors/Sysinternals/PsLogList","https://twitter.com/EricaZelic/status/1614075109827874817"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1087","attack.t1087.001","attack.t1087.002"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_psloglist.yml","techniques":["T1087","T1087.001","T1087.002"],"cves":[]},{"id":"b3ad3c0f-c949-47a1-a30e-b0491ccae876","title":"Uncommon Connection to Active Directory Web Services","author":"@kostastsale","status":"test","level":"medium","date":"2024-01-26","modified":null,"description":"Detects uncommon network connections to the Active Directory Web Services (ADWS) from processes not typically associated with ADWS management.\n","references":["https://medium.com/falconforce/soaphound-tool-to-collect-active-directory-data-via-adws-165aca78288c","https://github.com/FalconForceTeam/FalconFriday/blob/a9219dfcfd89836f34660223f47d766982bdce46/Discovery/ADWS_Connection_from_Unexpected_Binary-Win.md"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.discovery","attack.t1087"],"path":"rules/windows/network_connection/net_connection_win_adws_unusual_connection.yml","techniques":["T1087"],"cves":[]},{"id":"beaa66d6-aa1b-4e3c-80f5-e0145369bfaf","title":"Potentially Suspicious EventLog Recon Activity Using Log Query Utilities","author":"Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems)","status":"test","level":"medium","date":"2022-09-09","modified":"2025-12-02","description":"Detects execution of different log query utilities and commands to search and dump the content of specific event logs or look for specific event IDs.\nThis technique is used by threat actors in order to extract sensitive information from events logs such as usernames, IP addresses, hostnames, etc.\n","references":["http://blog.talosintelligence.com/2022/09/lazarus-three-rats.html","https://thedfirreport.com/2023/10/30/netsupport-intrusion-results-in-domain-compromise/","https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a","https://www.group-ib.com/blog/apt41-world-tour-2021/","https://labs.withsecure.com/content/dam/labs/docs/f-secureLABS-tlp-white-lazarus-threat-intel-report2.pdf","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.diagnostics/get-winevent?view=powershell-7.3","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-eventlog?view=powershell-5.1","http://www.solomonson.com/posts/2010-07-09-reading-eventviewer-command-line/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil","https://ptsecurity.com/research/pt-esc-threat-intelligence/striking-panda-attacks-apt31-today","https://www.cybertriage.com/artifact/terminalservices_remoteconnectionmanager_log/","https://ponderthebits.com/2018/02/windows-rdp-related-event-logs-identification-tracking-and-investigation/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.discovery","attack.t1552","attack.t1087"],"path":"rules/windows/process_creation/proc_creation_win_susp_eventlog_content_recon.yml","techniques":["T1552","T1087"],"cves":[]},{"id":"bed2a484-9348-4143-8a8a-b801c979301c","title":"Webshell Detection With Command Line Keywords","author":"Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Anton Kutepov, oscd.community, Chad Hudson, Matt Anderson","status":"test","level":"high","date":"2017-01-01","modified":"2026-07-14","description":"Detects certain command line parameters often used during reconnaissance activity via web shells","references":["https://www.fireeye.com/blog/threat-research/2013/08/breaking-down-the-china-chopper-web-shell-part-ii.html","https://unit42.paloaltonetworks.com/bumblebee-webshell-xhunt-campaign/","https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.discovery","attack.t1505.003","attack.t1018","attack.t1033","attack.t1087"],"path":"rules/windows/process_creation/proc_creation_win_webshell_recon_commands_and_processes.yml","techniques":["T1505.003","T1018","T1033","T1087"],"cves":[]},{"id":"e6313acd-208c-44fc-a0ff-db85d572e90e","title":"Network Reconnaissance Activity","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-02-07","modified":null,"description":"Detects a set of suspicious network related commands often used in recon stages","references":["https://thedfirreport.com/2022/02/07/qbot-likes-to-move-it-move-it/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1087","attack.t1082","car.2016-03-001"],"path":"rules/windows/process_creation/proc_creation_win_nslookup_domain_discovery.yml","techniques":["T1087","T1082"],"cves":[]},{"id":"e92a4287-e072-4a40-9739-370c106bb750","title":"HackTool - SOAPHound Execution","author":"@kostastsale","status":"test","level":"high","date":"2024-01-26","modified":null,"description":"Detects the execution of SOAPHound, a .NET tool for collecting Active Directory data, using specific command-line arguments that may indicate an attempt to extract sensitive AD information.\n","references":["https://github.com/FalconForceTeam/SOAPHound","https://medium.com/falconforce/soaphound-tool-to-collect-active-directory-data-via-adws-165aca78288c"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1087"],"path":"rules/windows/process_creation/proc_creation_win_hktl_soaphound_execution.yml","techniques":["T1087"],"cves":[]},{"id":"fa3c117a-bc0d-416e-a31b-0c0e80653efb","title":"Chopper Webshell Process Pattern","author":"Florian Roth (Nextron Systems), MSTI (query)","status":"test","level":"high","date":"2022-10-01","modified":null,"description":"Detects patterns found in process executions cause by China Chopper like tiny (ASPX) webshells","references":["https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.discovery","attack.t1505.003","attack.t1018","attack.t1033","attack.t1087"],"path":"rules/windows/process_creation/proc_creation_win_webshell_chopper.yml","techniques":["T1505.003","T1018","T1033","T1087"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-13161","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2024-13160","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2024-13159","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-27532","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2022-41082","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-44515","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}