Analytics
Low
✕
Multiple discovery commands on a Windows host by the same process
The alerted process performed multiple discovery commands in a short timeframe.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Remote System Discovery (T1018) System Information Discovery (T1082) System Network Configuration Discovery (T1016) System Service Discovery (T1007)
Attacker's goals:
Collect information about the host, network and user configuration for lateral movement and privilege escalation.
Investigative actions:
Verify if the script or process initiating the discovery commands is benign. Verify that this isn't sanctioned IT activity. Look for other hosts executing similar commands.
- Test period:
- 10 Minutes
- Deduplication:
- 1 Day
5 variations:
- Remote Multiple discovery commands on a Windows host by the same IP High (parent: Low) Adds Remote Services (T1021)
- Multiple discovery commands on a Windows host by the same process from a web server CGO Medium (parent: Low) Adds Server Software Component: Web Shell (T1505.003)
- Multiple discovery commands on a Windows host by the same process from an SQL server CGO Medium (parent: Low) Adds Server Software Component: SQL Stored Procedures (T1505.001)
- Multiple discovery commands on a Windows host by the same process from a remote CGO Medium (parent: Low) Adds Remote Services (T1021)
- Rare Multiple discovery commands on a Windows host by the same process Medium (parent: Low)