Local group enumeration via RPC
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Permission Groups Discovery: Local Groups (T1069.001), Permission Groups Discovery (T1069)
Severity
Informational
Description
A user enumerated local groups via RPC.
Attacker's Goals
An adversary may leverage local groups discovery to identify privileged groups and escalate privileges.
Investigative actions
Determine the user, hostname, and process that performed the group enumeration.
Inspect process, command-line arguments or scripts used.
Check for any privilege escalation or lateral movement attempts from the source system.
Check if the tool used to enumerate the local groups is a known or an approved tool.
Review the logs for suspicious activity from the same host or user.
Variations
Was this helpful?
