Analytics BIOC Informational

LDAP traffic from non-standard process

LDAP traffic is usually performed by a standard set of processes. The endpoint had a non-standard process communicating over ports normally used by LDAP. This may be indicative of Active Directory domain enumeration, which may be used during attacks against the organization.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Account Discovery (T1087)
Attacker's goals:

An attacker is attempting to enumerate Active Directory.

Investigative actions:

Make sure the process is not a scanner that implements its version of the protocol, and that the scanner use is for sanctioned purposes. For example, nmap enumerating LDAP. Make sure the process is not a sanctioned security product that creates standalone binaries for its use. For example, Illusive Network honeypots. Investigate the process to see if the high-level language used to implement the application is the source of the alert. Some high-level programming languages provide their protocol implementations. Examine the endpoint to see if it is infected with malware. If the parent-child chain of initiating processes has been infiltrated with a malicious replacement, then that replacement could be known malware.

Test period:
N/A (single event)
Deduplication:
1 Day
4 variations:
  • LDAP traffic from reverse SSH tunnel Medium (parent: Informational)
  • LDAP traffic from non-standard and uncommon process Low (parent: Informational)
  • LDAP traffic from non-standard process executed under an unsigned causality actor in a commonly abused directory Low (parent: Informational)
  • LDAP traffic from an injected thread within a non-standard process Low (parent: Informational)