User and Group Enumeration via SAMR
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
10 Minutes
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Account Discovery (T1087), Permission Groups Discovery (T1069)
Severity
Informational
Description
The endpoint performed unfamiliar SAMR querying activity to a domain controller.
Attacker's Goals
An adversary may enumerate users and groups to gain information and plan its lateral movement over the network.
Investigative actions
Check if the host is a newly deployed server that provides RPC-based services to multiple hosts.
Check if there are any other suspicious activities originating from the same machine.
PreviousUser added to the SMS Admins local group
NextUser attempted to connect from a suspicious country
Was this helpful?
