For the complete documentation index, see llms.txt. This page is also available as Markdown.

Multiple discovery commands on a Windows host by the same process

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

10 Minutes

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

Low

Description

The alerted process performed multiple discovery commands in a short timeframe.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Variations

Remote Multiple discovery commands on a Windows host by the same IP

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008), Discovery (TA0007)

ATT&CK Technique

Remote Services (T1021), Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

High

Description

The alerted process performed multiple discovery commands in a short timeframe.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Multiple discovery commands on a Windows host by the same process from a web server CGO

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Discovery (TA0007)

ATT&CK Technique

Server Software Component: Web Shell (T1505.003), Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

Medium

Description

The alerted process performed multiple discovery commands in a short timeframe.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Multiple discovery commands on a Windows host by the same process from an SQL server CGO

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Discovery (TA0007)

ATT&CK Technique

Server Software Component: SQL Stored Procedures (T1505.001), Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

Medium

Description

The alerted process performed multiple discovery commands in a short timeframe.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Multiple discovery commands on a Windows host by the same process from a remote CGO

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008), Discovery (TA0007)

ATT&CK Technique

Remote Services (T1021), Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

Medium

Description

The alerted process performed multiple discovery commands in a short timeframe.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Rare Multiple discovery commands on a Windows host by the same process

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

Medium

Description

The alerted process performed multiple discovery commands in a short timeframe.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Was this helpful?