Multiple discovery commands on a Linux host by the same process
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
10 Minutes
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)
Severity
Informational
Description
The alerted process performed multiple consecutive discovery commands in a short timeframe.
Attacker's Goals
Collect information about the host, network and user configuration for lateral movement and privilege escalation.
Investigative actions
Verify if the script or process initiating the discovery commands is benign.
Verify that this isn't sanctioned IT activity.
Look for other hosts executing similar commands.
Variations
PreviousMultiple cloud snapshots export
NextMultiple discovery commands on a Windows host by the same process
Was this helpful?
