BIOC
Informational
✕
Permission groups discovery via ldapsearch
Attackers may use the ldapsearch command-line tool to gather information about domain groups and their permissions.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Discovery
- Status:
- Enabled
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Permission Groups Discovery (T1069)
Indicator:
Process action type = execution AND target process cmd =~ objectClass|=\*|objectCategory|servicePrincipalName|adminCount|samAccountType AND target process name = ldapsearch Process cgo name != adclient Host host os = linux
Preventable: yes