Remote account enumeration
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
10 Minutes
Deduplication Period
1 Day
Required Data
XDR Agent
Detection Modules
Identity Analytics
ATT&CK Tactic
Discovery (TA0007), Credential Access (TA0006)
ATT&CK Technique
Account Discovery (T1087), Brute Force (T1110)
Severity
Informational
Description
Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts.
Attacker's Goals
Discover valid accounts to gain credentials.
Investigative actions
Check if the login attempts were part of a legitimate misunderstanding of the system or part of an attack.
Variations
PreviousRegistration of Uncommon .NET Services and/or Assemblies
NextRemote code execution into Kubernetes Pod
Was this helpful?
