For the complete documentation index, see llms.txt. This page is also available as Markdown.

Local group enumeration via RPC

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Permission Groups Discovery: Local Groups (T1069.001), Permission Groups Discovery (T1069)

Severity

Informational

Description

A user enumerated local groups via RPC.

Attacker's Goals

An adversary may leverage local groups discovery to identify privileged groups and escalate privileges.

Investigative actions

  • Determine the user, hostname, and process that performed the group enumeration.

  • Inspect process, command-line arguments or scripts used.

  • Check for any privilege escalation or lateral movement attempts from the source system.

  • Check if the tool used to enumerate the local groups is a known or an approved tool.

  • Review the logs for suspicious activity from the same host or user.

Variations

Remote local group enumeration via RPC

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Permission Groups Discovery: Local Groups (T1069.001), Permission Groups Discovery (T1069)

Severity

Informational

Description

A user enumerated local groups via RPC.

Attacker's Goals

An adversary may leverage local groups discovery to identify privileged groups and escalate privileges.

Investigative actions

  • Determine the user, hostname, and process that performed the group enumeration.

  • Inspect process, command-line arguments or scripts used.

  • Check for any privilege escalation or lateral movement attempts from the source system.

  • Check if the tool used to enumerate the local groups is a known or an approved tool.

  • Review the logs for suspicious activity from the same host or user.

Was this helpful?