Back to Rule

Rule History

SID: 3321363 • Source: pawpatrules

Versions (2)

Version DetailsCurrent

Rev: 5Aug 29, 2024, 12:00 PM

🐾 - 🔔 Anonymous LDAP bind request - 🥷 Domain Account Discovery - T1087.002

alert tcp any any -> $HOME_NET 389 (msg:"🐾 - 🔔 Anonymous LDAP bind request - 🥷 Domain Account Discovery - T1087.002"; flow:to_server, established; flowbits:set,pptrls.ldapanonymousbindrequest; flowbits:isnotset,pptrls.ldapanonymousbindrequest; content:"|30 0c 02 01|"; startswith; content:"|60 07 02 01 03 04 00 80 00|"; fast_pattern; distance:1; endswith; reference:url,https://attack.mitre.org/techniques/T1087/002/; reference:url,https://ldap3.readthedocs.io/en/latest/bind.html#anonymous-bind; metadata:created_at 2024_08_29, updated_at 2024_08_29, signature_severity Major, attack_target Server_Endpoint, mitre_tactic_id TA0007, mitre_tactic_name Discovery, mitre_technique_id T1087_002, mitre_technique_name Account_Discovery_Domain_Account; sid:3321363; rev:5; classtype:attempted-recon;)

Aug 29, 2024, 12:00 PM

Aug 29, 2024, 12:00 PM

Aug 29, 2024, 9:00 PM

Aug 29, 2024, 9:00 PM

rules/PAW-PATRULES_LATERAL_MOVEMENT.rules