Multiple discovery commands on a Windows host by the same process
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
10 Minutes
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)
Severity
Low
Description
The alerted process performed multiple discovery commands in a short timeframe.
Attacker's Goals
Collect information about the host, network and user configuration for lateral movement and privilege escalation.
Investigative actions
Verify if the script or process initiating the discovery commands is benign.
Verify that this isn't sanctioned IT activity.
Look for other hosts executing similar commands.
Variations
PreviousMultiple discovery commands on a Linux host by the same process
NextMultiple discovery commands
Was this helpful?
