MITRE ATT&CK technique
Remote System Discovery detection rulesT1018
Remote System Discovery (T1018) is a MITRE ATT&CK technique in the Discovery tactic. This page lists the 17 community-maintained Sigma detection rules in the library mapped to T1018 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, cisco, linux.
Chopper Webshell Process Pattern
highDetects patterns found in process executions cause by China Chopper like tiny (ASPX) webshells
windows · process_creation
HackTool - NetExec Execution
highDetects execution of the hacktool NetExec. NetExec (formerly CrackMapExec) is a widely used post-exploitation tool designed for Active Directory penetration testing and network enumeration In enterprise environments, the use of NetExec is considered suspicious or potentially malicious because it enables attackers to enumerate hosts, exploit network services, and move laterally across systems. Threat actors and red teams commonly use NetExec to identify vulnerable systems, harvest credentials, and execute commands remotely.
windows · process_creation
PUA - AdFind Suspicious Execution
highDetects AdFind execution with common flags seen used during attacks
windows · process_creation
Renamed AdFind Execution
highDetects the use of a renamed Adfind.exe. AdFind continues to be seen across majority of breaches. It is used to domain trust discovery to plan out subsequent steps in the attack chain.
windows · process_creation
Webshell Detection With Command Line Keywords
highDetects certain command line parameters often used during reconnaissance activity via web shells
windows · process_creation
Webshell Hacking Activity Patterns
highDetects certain parent child patterns found in cases in which a web shell is used to perform certain credential dumping or exfiltration activities on a compromised system
windows · process_creation
DirectorySearcher Powershell Exploitation
mediumEnumerates Active Directory to determine computers that are joined to the domain
windows · ps_script
Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock
mediumDetects the use of the "Get-ADComputer" cmdlet in order to identify systems which are configured for unconstrained delegation.
windows · ps_script
Suspicious Scan Loop Network
mediumAdversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system
windows · process_creation
Active Directory Computers Enumeration With Get-AdComputer
lowDetects usage of the "Get-AdComputer" to enumerate Computers or properties within Active Directory.
windows · ps_script
Cisco Discovery
lowFind information about network devices that is not stored in config files
cisco
Linux Remote System Discovery
lowDetects the enumeration of other remote systems.
linux · process_creation
Net.EXE Execution
lowDetects execution of "Net.EXE".
windows · process_creation
Nltest.EXE Execution
lowDetects nltest commands that can be used for information discovery
windows · process_creation
PUA - Adidnsdump Execution
lowThis tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks Python 3 and python.exe must be installed, Usee to Query/modify DNS records for Active Directory integrated DNS via LDAP
windows · process_creation
Share And Session Enumeration Using Net.EXE
lowDetects attempts to enumerate file shares, printer shares and sessions using "net.exe" with the "view" flag.
windows · process_creation
Macos Remote System Discovery
informationalDetects the enumeration of other remote systems.
macos · process_creation