Analytics BIOC Medium

Suspicious Encrypting File System Remote call (EFSRPC) to domain controller

An Encrypting File System Remote call (EFSRPC) was made to a domain controller.

Module:
Platform Analytics
Data source:
Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Use Alternate Authentication Material: Pass the Hash (T1550.002)
Attacker's goals:

An attacker is attempting to steal credentials and move laterally within a network.

Investigative actions:

Check for suspicious processes on the host. Check if the source host is a vulnerability scanner. Look for following suspicious connections using the DC machine account.

Test period:
N/A (single event)
Deduplication:
1 Day