Analytics BIOC
Medium
✕
Suspicious Encrypting File System Remote call (EFSRPC) to domain controller
An Encrypting File System Remote call (EFSRPC) was made to a domain controller.
- Module:
- Platform Analytics
- Data source:
- Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Use Alternate Authentication Material: Pass the Hash (T1550.002)
Attacker's goals:
An attacker is attempting to steal credentials and move laterally within a network.
Investigative actions:
Check for suspicious processes on the host. Check if the source host is a vulnerability scanner. Look for following suspicious connections using the DC machine account.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day