MITRE ATT&CK technique
Account Discovery detection rulesT1087
Account Discovery (T1087) is a MITRE ATT&CK technique in the Discovery tactic. This page lists the 41 community-maintained Sigma detection rules in the library mapped to T1087 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, azure, rpc_firewall.
AD Privileged Users or Groups Reconnaissance
highDetect priv users or groups recon based on 4661 eventid and known privileged users or groups SIDs
windows
BloodHound Collection Files
highDetects default file names outputted by the BloodHound collection tool SharpHound
windows · file_event
Chopper Webshell Process Pattern
highDetects patterns found in process executions cause by China Chopper like tiny (ASPX) webshells
windows · process_creation
Discovery Using AzureHound
highDetects AzureHound (A BloodHound data collector for Microsoft Azure) activity via the default User-Agent that is used during its operation after successful authentication.
azure
HackTool - Bloodhound/Sharphound Execution
highDetects command line parameters used by Bloodhound and Sharphound hack tools
windows · process_creation
HackTool - SOAPHound Execution
highDetects the execution of SOAPHound, a .NET tool for collecting Active Directory data, using specific command-line arguments that may indicate an attempt to extract sensitive AD information.
windows · process_creation
HackTool - winPEAS Execution
highWinPEAS is a script that search for possible paths to escalate privileges on Windows hosts. The checks are explained on book.hacktricks.xyz
windows · process_creation
Hacktool Ruler
highThis events that are generated when using the hacktool Ruler by Sensepost
windows
Malicious PowerShell Commandlets - PoshModule
highDetects Commandlet names from well-known PowerShell exploitation frameworks
windows · ps_module
Malicious PowerShell Commandlets - ProcessCreation
highDetects Commandlet names from well-known PowerShell exploitation frameworks
windows · process_creation
Malicious PowerShell Commandlets - ScriptBlock
highDetects Commandlet names from well-known PowerShell exploitation frameworks
windows · ps_script
Network Reconnaissance Activity
highDetects a set of suspicious network related commands often used in recon stages
windows · process_creation
Potential Pikabot Discovery Activity
highDetects system discovery activity carried out by Pikabot, such as incl. network, user info and domain groups. The malware Pikabot has been seen to use this technique as part of its C2-botnet registration with a short collection time frame (less than 1 minute).
windows · process_creation
PUA - AdFind Suspicious Execution
highDetects AdFind execution with common flags seen used during attacks
windows · process_creation
PUA - Seatbelt Execution
highDetects the execution of the PUA/Recon tool Seatbelt via PE information of command line parameters
windows · process_creation
PUA - Suspicious ActiveDirectory Enumeration Via AdFind.EXE
highDetects active directory enumeration activity using known AdFind CLI flags
windows · process_creation
Reconnaissance Activity
highDetects activity as "net user administrator /domain" and "net group domain admins /domain"
windows
Renamed AdFind Execution
highDetects the use of a renamed Adfind.exe. AdFind continues to be seen across majority of breaches. It is used to domain trust discovery to plan out subsequent steps in the attack chain.
windows · process_creation
SharpHound Recon Account Discovery
highDetects remote RPC calls useb by SharpHound to map remote connections and local group membership.
rpc_firewall · application
Suspicious Active Directory Database Snapshot Via ADExplorer
highDetects the execution of Sysinternals ADExplorer with the "-snapshot" flag in order to save a local copy of the active directory database to a suspicious directory. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
windows · process_creation
Webshell Detection With Command Line Keywords
highDetects certain command line parameters often used during reconnaissance activity via web shells
windows · process_creation
Webshell Hacking Activity Patterns
highDetects certain parent child patterns found in cases in which a web shell is used to perform certain credential dumping or exfiltration activities on a compromised system
windows · process_creation
Active Directory Database Snapshot Via ADExplorer
mediumDetects the execution of Sysinternals ADExplorer with the "-snapshot" flag in order to save a local copy of the active directory database. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
windows · process_creation
Active Directory Structure Export Via Csvde.EXE
mediumDetects the execution of "csvde.exe" in order to export organizational Active Directory structure.
windows · process_creation
ADExplorer Writing Complete AD Snapshot Into .dat File
mediumDetects the dual use tool ADExplorer writing a complete AD snapshot into a .dat file. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
windows · file_event
AWS STS GetCallerIdentity Enumeration Via TruffleHog
mediumDetects the use of TruffleHog for AWS credential validation by identifying GetCallerIdentity API calls where the userAgent indicates TruffleHog. Threat actors leverage TruffleHog to enumerate and validate exposed AWS keys. Successful exploitation allows threat actors to confirm the validity of compromised AWS credentials, facilitating further unauthorized access and actions within the AWS environment.
aws
Potential Active Directory Reconnaissance/Enumeration Via LDAP
mediumDetects potential Active Directory enumeration via LDAP
windows
Potential AD User Enumeration From Non-Machine Account
mediumDetects read access to a domain user from a non-machine account
windows
Potentially Suspicious EventLog Recon Activity Using Log Query Utilities
mediumDetects execution of different log query utilities and commands to search and dump the content of specific event logs or look for specific event IDs. This technique is used by threat actors in order to extract sensitive information from events logs such as usernames, IP addresses, hostnames, etc.
windows · process_creation
PUA - AdFind.EXE Execution
mediumDetects execution of Adfind.exe utility, which can be used for reconnaissance in an Active Directory environment
windows · process_creation
Suspicious Group And Account Reconnaissance Activity Using Net.EXE
mediumDetects suspicious reconnaissance command line activity on Windows systems using Net.EXE Check if the user that executed the commands is suspicious (e.g. service accounts, LOCAL_SYSTEM)
windows · process_creation
Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet
mediumDetects suspicious reconnaissance command line activity on Windows systems using the PowerShell Get-LocalGroupMember Cmdlet
windows · process_creation
Suspicious Use of PsLogList
mediumDetects usage of the PsLogList utility to dump event log in order to extract admin accounts and perform account discovery or delete events logs
windows · process_creation
Uncommon Connection to Active Directory Web Services
mediumDetects uncommon network connections to the Active Directory Web Services (ADWS) from processes not typically associated with ADWS management.
windows · network_connection
Active Directory Computers Enumeration With Get-AdComputer
lowDetects usage of the "Get-AdComputer" to enumerate Computers or properties within Active Directory.
windows · ps_script
Cisco Collect Data
lowCollect pertinent data from the configuration files
cisco
Local Accounts Discovery
lowLocal accounts, System Owner/User discovery using operating systems utilities
windows · process_creation
Local System Accounts Discovery - Linux
lowDetects enumeration of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.
linux · process_creation
Local System Accounts Discovery - MacOs
lowDetects enumeration of local system accounts on MacOS systems. This can be used by attackers to identify accounts for lateral movement or privilege escalation.
macos · process_creation
Net.EXE Execution
lowDetects execution of "Net.EXE".
windows · process_creation
RBAC Permission Enumeration Attempt
lowDetects identities attempting to enumerate their Kubernetes RBAC permissions. In the early stages of a breach, attackers will aim to list the permissions they have within the compromised environment. In a Kubernetes cluster, this can be achieved by interacting with the API server, and querying the SelfSubjectAccessReview API via e.g. a "kubectl auth can-i --list" command. This will enumerate the Role-Based Access Controls (RBAC) rules defining the compromised user's authorization.
kubernetes · application