Versions (2)
Version DetailsCurrent
Rev: 7 • Nov 27, 2023, 12:00 PM🐾 - 🔔 LDAP user type object creation request on 🪟 Active Directory - 🥷 - T1136.002
alert tcp any any -> $HOME_NET 389 (msg:"🐾 - 🔔 LDAP user type object creation request on 🪟 Active Directory - 🥷 - T1136.002"; flow: to_server, established; flowbits:set,pptrls.ldapcreateuserad; flowbits:isnotset,pptrls.ldapcreateuserad; content:"|02 01|"; content:"|68|"; distance:1; content:"|43 4e 3d|"; content:"|04 0b 6f 62 6a 65 63 74 43 6c 61 73 73|"; content:"|75 73 65 72|"; content:!"|63 6f 6d 70 75 74 65 72|"; content:"sAMAccountName"; nocase; fast_pattern; reference:url,https://attack.mitre.org/techniques/T1136/002/; reference:url,https://ldap3.readthedocs.io/en/latest/add.html; metadata:created_at 2023_11_27, updated_at 2024_10_02, signature_severity Major, attack_target Server_Endpoint, mitre_tactic_id TA0003, mitre_tactic_name Persistence, mitre_technique_id T1136_002, mitre_technique_name Create_Account_Domain_Account; sid:3301104; rev:7; classtype:attempted-recon;)
Nov 27, 2023, 12:00 PM
Oct 2, 2024, 12:00 PM
Feb 21, 2024, 4:00 PM
May 29, 2025, 11:12 PM
rules/PAW-PATRULES_LATERAL_MOVEMENT.rules