Analytics
Informational
✕
User and Group Enumeration via SAMR
The endpoint performed unfamiliar SAMR querying activity to a domain controller.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Account Discovery (T1087) Permission Groups Discovery (T1069)
Attacker's goals:
An adversary may enumerate users and groups to gain information and plan its lateral movement over the network.
Investigative actions:
Check if the host is a newly deployed server that provides RPC-based services to multiple hosts. Check if there are any other suspicious activities originating from the same machine.
- Test period:
- 10 Minutes
- Deduplication:
- 1 Day