Suspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdlet
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Remote System Discovery (T1018)
Severity
Informational
Description
An attacker may use one of Microsoft's Active Directory PowerShell module remote discovery cmdlet to reconnaissance the network.
Attacker's Goals
Collect information about the host, network and user configuration for lateral movement and privilege escalation.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
Understand what information the attacker had gathered from the command and investigate relevant assets.
Was this helpful?
