For the complete documentation index, see llms.txt. This page is also available as Markdown.

User and Group Enumeration via SAMR

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

10 Minutes

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Account Discovery (T1087), Permission Groups Discovery (T1069)

Severity

Informational

Description

The endpoint performed unfamiliar SAMR querying activity to a domain controller.

Attacker's Goals

An adversary may enumerate users and groups to gain information and plan its lateral movement over the network.

Investigative actions

  • Check if the host is a newly deployed server that provides RPC-based services to multiple hosts.

  • Check if there are any other suspicious activities originating from the same machine.

Was this helpful?