Suspicious Encrypting File System Remote call (EFSRPC) to domain controller
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Palo Alto Networks Firewall EAL Logs OR XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Lateral Movement (TA0008)
ATT&CK Technique
Use Alternate Authentication Material: Pass the Hash (T1550.002)
Severity
Medium
Description
An Encrypting File System Remote call (EFSRPC) was made to a domain controller.
Attacker's Goals
An attacker is attempting to steal credentials and move laterally within a network.
Investigative actions
Check for suspicious processes on the host.
Check if the source host is a vulnerability scanner.
Look for following suspicious connections using the DC machine account.
Was this helpful?
