Analytics BIOC
Informational
✕
Possible GPO Enumeration
A possible GPO enumeration via LDAP was performed. Such enumeration may be used during attacks against the organization.
- Module:
- Identity Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Group Policy Discovery (T1615)
Detector tags: LDAP Analytics (Client) LDAP Analytics (Server)
Attacker's goals:
An attacker is attempting to enumerate Active Directory.
Investigative actions:
Investigate the LDAP search query for any suspicious indicators. Look for additional LDAP queries the user executed that might be suspicious. Determine whether the search query is generic. Wide search queries (often using wildcards) tend to be more suspicious. In our case, we are looking for targeted search queries. Check if the process executes LDAP search queries as part of its normal behavior.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Suspicious GPO Enumeration by an LDAP tool Medium (parent: Informational)
- Possible GPO Enumeration by a Suspicious Process Low (parent: Informational)