Analytics BIOC Medium

Suspicious PowerSploit's recon module (PowerView) used to search for exposed hosts

An attacker may use PowerSploit to reconnaissance the network for exposed hosts to move laterally to.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Remote System Discovery (T1018)
Attacker's goals:

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions:

Verify that the relevant function was indeed run by PowerSploit (https://powersploit.readthedocs.io/#recon). Understand what information the attacker had gathered from the command and investigate relevant assets.

Test period:
N/A (single event)
Deduplication:
1 Day