For the complete documentation index, see llms.txt. This page is also available as Markdown.

Multiple discovery commands

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

10 Minutes

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

Low

Description

The alerted causality performed multiple discovery commands in a short timeframe.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Variations

Multiple discovery commands from a web server CGO

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Discovery (TA0007)

ATT&CK Technique

Server Software Component: Web Shell (T1505.003), Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

Medium

Description

The alerted causality performed multiple discovery commands in a short timeframe.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Multiple discovery commands from an SQL server CGO

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Discovery (TA0007)

ATT&CK Technique

Server Software Component: SQL Stored Procedures (T1505.001), Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

Medium

Description

The alerted causality performed multiple discovery commands in a short timeframe.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Multiple discovery commands from an unsigned causality

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

Medium

Description

The alerted causality performed multiple discovery commands in a short timeframe.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Multiple discovery commands from a standard IT tool

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

Informational

Description

The alerted causality performed multiple discovery commands in a short timeframe.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Was this helpful?