For the complete documentation index, see llms.txt. This page is also available as Markdown.

Multiple discovery-like commands

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

10 Minutes

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

Informational

Description

The alerted process performed multiple consecutive discovery commands in a short time frame.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Variations

Multiple discovery-like commands by web server process

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

Low

Description

The web server process performed multiple consecutive discovery commands in a short time frame.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Multiple discovery-like commands on a Linux host

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

Informational

Description

The alerted process performed multiple consecutive discovery commands in a short time frame.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Multiple discovery-like commands

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Remote System Discovery (T1018), System Information Discovery (T1082), System Network Configuration Discovery (T1016), System Service Discovery (T1007)

Severity

Informational

Description

The alerted process performed multiple consecutive discovery commands in a short time frame.

Attacker's Goals

Collect information about the host, network and user configuration for lateral movement and privilege escalation.

Investigative actions

  • Verify if the script or process initiating the discovery commands is benign.

  • Verify that this isn't sanctioned IT activity.

  • Look for other hosts executing similar commands.

Was this helpful?