MITRE ATT&CK technique
Domain Trust Discovery detection rulesT1482
Domain Trust Discovery (T1482) is a MITRE ATT&CK technique in the Discovery tactic. This page lists the 17 community-maintained Sigma detection rules in the library mapped to T1482 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
BloodHound Collection Files
highDetects default file names outputted by the BloodHound collection tool SharpHound
windows · file_event
HackTool - Bloodhound/Sharphound Execution
highDetects command line parameters used by Bloodhound and Sharphound hack tools
windows · process_creation
HackTool - SharpView Execution
highAdversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
windows · process_creation
HackTool - TruffleSnout Execution
highDetects the use of TruffleSnout.exe an iterative AD discovery toolkit for offensive operators, situational awareness and targeted low noise enumeration.
windows · process_creation
Malicious PowerShell Commandlets - PoshModule
highDetects Commandlet names from well-known PowerShell exploitation frameworks
windows · ps_module
Malicious PowerShell Commandlets - ProcessCreation
highDetects Commandlet names from well-known PowerShell exploitation frameworks
windows · process_creation
Malicious PowerShell Commandlets - ScriptBlock
highDetects Commandlet names from well-known PowerShell exploitation frameworks
windows · ps_script
PUA - AdFind Suspicious Execution
highDetects AdFind execution with common flags seen used during attacks
windows · process_creation
Renamed AdFind Execution
highDetects the use of a renamed Adfind.exe. AdFind continues to be seen across majority of breaches. It is used to domain trust discovery to plan out subsequent steps in the attack chain.
windows · process_creation
Suspicious Active Directory Database Snapshot Via ADExplorer
highDetects the execution of Sysinternals ADExplorer with the "-snapshot" flag in order to save a local copy of the active directory database to a suspicious directory. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
windows · process_creation
Active Directory Database Snapshot Via ADExplorer
mediumDetects the execution of Sysinternals ADExplorer with the "-snapshot" flag in order to save a local copy of the active directory database. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
windows · process_creation
ADExplorer Writing Complete AD Snapshot Into .dat File
mediumDetects the dual use tool ADExplorer writing a complete AD snapshot into a .dat file. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
windows · file_event
Domain Trust Discovery Via Dsquery
mediumDetects execution of "dsquery.exe" for domain trust discovery
windows · process_creation
Potential Active Directory Reconnaissance/Enumeration Via LDAP
mediumDetects potential Active Directory enumeration via LDAP
windows
Potential Recon Activity Via Nltest.EXE
mediumDetects nltest commands that can be used for information discovery
windows · process_creation
DNS Server Discovery Via LDAP Query
lowDetects DNS server discovery via LDAP query requests from uncommon applications
windows · dns_query
Nltest.EXE Execution
lowDetects nltest commands that can be used for information discovery
windows · process_creation