Analytics Informational

Multiple discovery commands on a Linux host by the same process

The alerted process performed multiple consecutive discovery commands in a short timeframe.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Remote System Discovery (T1018) System Information Discovery (T1082) System Network Configuration Discovery (T1016) System Service Discovery (T1007)
Attacker's goals:

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions:

Verify if the script or process initiating the discovery commands is benign. Verify that this isn't sanctioned IT activity. Look for other hosts executing similar commands.

Test period:
10 Minutes
Deduplication:
1 Day
2 variations:
  • Multiple discovery commands on a Linux host by the same process Medium (parent: Informational)
  • Multiple discovery commands on a Linux host by the same process Low (parent: Informational)