Local group enumeration
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
5 Minutes
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Permission Groups Discovery: Local Groups (T1069.001), Permission Groups Discovery (T1069)
Severity
Informational
Description
A user performed an enumeration on local groups to retrieve their details.
Attacker's Goals
An adversary may leverage local groups discovery to identify privileged groups and escalate privileges.
Investigative actions
Determine the user, hostname, and process that performed the group enumeration.
Inspect process, command-line arguments or scripts used.
Check for any privilege escalation or lateral movement attempts from the source system.
Check if the tool used to enumerate the local groups is a known or an approved tool.
Review the logs for suspicious activity from the same host or user.
Variations
Was this helpful?
