Cross-source coverage
T1087.002 / ATT&CK
Account Discovery: Domain Account
77 rules across 7 sources.
1 atomic-IOC hidden · include
From MITRE ATT&CK 19.2
Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges.
Commands such as net user /domain and net group /domain of the Net utility, dscacheutil -q group on macOS, and ldapsearch on Linux can list domain users and groups. PowerShell cmdlets including Get-ADUser and Get-ADGroupMember may enumerate members of Active Directory groups.
- Tactics
- Discovery
- Platforms
- Linux · macOS · Windows
- Telemetry
-
WinEventLog:SysmonWinEventLog:PowerShellNSM:Flowauditd:SYSCALLlinuxsyslogmacos:unifiedlog
How MITRE says to detect it DET0129
Domain Account Enumeration Across Platforms
Windows Analytic 0363
Adversary enumeration of domain accounts using net.exe, PowerShell, WMI, or LDAP queries from non-domain controllers or non-admin endpoints.
WinEventLog:SysmonEventCode=1WinEventLog:PowerShellEventCode=4103, 4104, 4105, 4106NSM:FlowLDAP Bind/Search
Linux Analytic 0364
Domain account enumeration using ldapsearch, samba tools (e.g., 'wbinfo -u'), or winbindd lookups.
auditd:SYSCALLexecvelinuxsyslognslcd or winbind logsNSM:FlowLDAP Query
macOS Analytic 0365
Domain group and user enumeration via dscl or dscacheutil, or queries to directory services from non-admin endpoints.
macos:unifiedlogProcess Executionmacos:unifiedlogDS daemon log entries
splunk/security_content
28 rules| Detection | Severity | Format |
|---|---|---|
| AdsiSearcher Account Discovery | Undefined | SPL |
| Detect AzureHound Command-Line Arguments | Undefined | SPL |
| Detect AzureHound File Modifications | Undefined | SPL |
| Detect SharpHound Command-Line Arguments | Undefined | SPL |
| Detect SharpHound File Modifications | Undefined | SPL |
| Detect SharpHound Usage | Undefined | SPL |
| Domain Account Discovery with Dsquery | Undefined | SPL |
| Domain Account Discovery with Wmic | Undefined | SPL |
| Get ADUser with PowerShell | Undefined | SPL |
| Get ADUser with PowerShell Script Block | Undefined | SPL |
+ 18 more from splunk/security_content → showing the 10 highest-severity
SigmaHQ/sigma
21 rules| Detection | Severity | Format |
|---|---|---|
| AD Privileged Users or Groups Reconnaissance | High | Sigma |
| BloodHound Collection Files | High | Sigma |
| HackTool - Bloodhound/Sharphound Execution | High | Sigma |
| Malicious PowerShell Commandlets - PoshModule | High | Sigma |
| Malicious PowerShell Commandlets - ProcessCreation | High | Sigma |
| Malicious PowerShell Commandlets - ScriptBlock | High | Sigma |
| PUA - AdFind Suspicious Execution | High | Sigma |
| PUA - Suspicious ActiveDirectory Enumeration Via AdFind.EXE | High | Sigma |
| Reconnaissance Activity | High | Sigma |
| Renamed AdFind Execution | High | Sigma |
+ 11 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/protections-artifacts
12 rules| Detection | Severity | Format |
|---|---|---|
| Active Directory Data Collection via LDAP | Undefined | Elastic TOML |
| AD Certificate Services Enumeration via LDAP | Undefined | Elastic TOML |
| Domain Accounts Enumeration via LDAP Search | Undefined | Elastic TOML |
| Domain Computers Enumeration via LDAP Search | Undefined | Elastic TOML |
| Domain Password Policy Enumeration via LDAP | Undefined | Elastic TOML |
| Domain Trust and Schema Enumeration via LDAP | Undefined | Elastic TOML |
| Group and Privileged Accounts Discovery via LDAP | Undefined | Elastic TOML |
| Password Spraying Enumeration via LDAP | Undefined | Elastic TOML |
| Privileged Domain Group Enumeration via LDAP | Undefined | Elastic TOML |
| Sensitive Attributes Discovery via LDAP | Undefined | Elastic TOML |
+ 2 more from elastic/protections-artifacts → showing the 10 highest-severity
elastic/detection-rules
8 rules| Detection | Severity | Format |
|---|---|---|
| Mounting Hidden or WebDav Remote Shares | Medium | Elastic TOML |
| Potential Enumeration via Active Directory Web Service | Medium | Elastic TOML |
| Active Directory Discovery using AdExplorer | Low | Elastic TOML |
| AdFind Command Activity | Low | Elastic TOML |
| Enumeration of Administrator Accounts | Low | Elastic TOML |
| Enumeration of Users or Groups via Built-in Commands | Low | Elastic TOML |
| PowerShell Suspicious Discovery Related Windows API Functions | Low | Elastic TOML |
| Suspicious Access to LDAP Attributes | Low | Elastic TOML |
socfortress/Wazuh-Rules
5 rules| Detection | Severity | Format |
|---|---|---|
| LDAP domain account enumeration attempt detected using ldapsearch (T1087.002) | High | Wazuh XML |
| Possible domain account enumeration using ldapdomaindump | High | Wazuh XML |
| Powershell script: Active Directory enumeration detected | High | Wazuh XML |
| Possible LDAP enumeration of domain groups using ldapsearch | Medium | Wazuh XML |
| Powershell script Executed · win.system.severityValue = VERBOSE | Low | Wazuh XML |
Bert-JanP/Hunting-Queries-Detection-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Anomalous Amount of LDAP traffic | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
Wazuh Core Ruleset
1 rule| Detection | Severity | Format |
|---|---|---|
| Powershell script "Get-NetUser executed". | Low | Wazuh XML |