Analytics Informational

User and Group Enumeration via SAMR

The endpoint performed unfamiliar SAMR querying activity to a domain controller.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Account Discovery (T1087) Permission Groups Discovery (T1069)
Attacker's goals:

An adversary may enumerate users and groups to gain information and plan its lateral movement over the network.

Investigative actions:

Check if the host is a newly deployed server that provides RPC-based services to multiple hosts. Check if there are any other suspicious activities originating from the same machine.

Test period:
10 Minutes
Deduplication:
1 Day