🐾 - 🔔 LDAP search request on whole subtree and all type of objects - Possible Domain Account Discovery 🥷 - T1087.002

SID: 3321257Rev: 1106 views
Sourcepawpatrules
CreatedMay 3, 2024
UpdatedMay 4, 2024
Classificationattempted-recon
alert tcp any any -> $HOME_NET 389 (msg:"🐾 - 🔔 LDAP search request on whole subtree and all type of objects - Possible Domain Account Discovery 🥷 - T1087.002"; flow:to_server, stateless; threshold:type limit, track by_src,count 1, seconds 60; content:"|44 43 3d|"; content:!"|43 4e 3d|"; content:"|0a 01 02 0a 01 03 02 01 00 02 01 00 01 01 00|"; content:"|6f 62 6a 65 63 74 43 6c 61 73 73 30 03 04 01 2a|"; fast_pattern; distance:2; reference:url,https://attack.mitre.org/techniques/T1087/002/; reference:url,https://github.com/p0dalirius/ldap2json; metadata:created_at 2024_05_04, updated_at 2024_05_04, signature_severity Major, attack_target Server_Endpoint, mitre_tactic_id TA00067, mitre_tactic_name Discovery, mitre_technique_id T1087_002, mitre_technique_name Account_Discovery_Domain_Account; sid:3321257; rev:1; classtype:attempted-recon;)

Metadata

created at2024_05_04
updated at2024_05_04
signature severityMajor
attack targetServer_Endpoint
mitre tactic idTA00067
mitre tactic nameDiscovery
mitre technique idT1087_002
mitre technique nameAccount_Discovery_Domain_Account

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!