🐾 - 🔔 LDAP computer type object creation request on 🪟 Active Directory - 🥷 - T1136.002

SID: 3301103Rev: 712 views
Sourcepawpatrules
CreatedNovember 27, 2023
UpdatedNovember 28, 2023
Classificationattempted-recon
alert tcp any any -> $HOME_NET 389 (msg:"🐾 - 🔔 LDAP computer type object creation request on 🪟 Active Directory - 🥷 - T1136.002"; flow:to_server, stateless; content:"|02 01|"; content:"|68|"; distance:1; content:"|43 4e 3d|"; content:"|04 0b 6f 62 6a 65 63 74 43 6c 61 73 73|"; content:"|63 6f 6d 70 75 74 65 72|"; content:"sAMAccountName"; nocase; fast_pattern; reference:url,https://attack.mitre.org/techniques/T1136/002/; reference:url,https://ldap3.readthedocs.io/en/latest/add.html; metadata:created_at 2023_11_27, updated_at 2023_11_28; sid:3301103; rev:7; classtype:attempted-recon;)

Metadata

created at2023_11_27
updated at2023_11_28

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!