🐾 - 🚨 Successful response to Anonymous LDAP bind request - 🥷 Domain Account Discovery - T1087.002

SID: 3321361Rev: 911 views
History
Sourcepawpatrules
CreatedAugust 29, 2024
UpdatedOctober 2, 2024
Classificationattempted-recon
alert tcp $HOME_NET 389 -> any any (msg:"🐾 - 🚨 Successful response to Anonymous LDAP bind request - 🥷 Domain Account Discovery - T1087.002"; flow:to_client, established; flowbits:isset,pptrls.ldapanonymousbindrequest; content:"|0a 01 00 04 00 04 00|"; reference:url,https://attack.mitre.org/techniques/T1087/002/; reference:url,https://ldap3.readthedocs.io/en/latest/bind.html#anonymous-bind; metadata:created_at 2024_08_29, updated_at 2024_10_02, signature_severity Major, attack_target Server_Endpoint, mitre_tactic_id TA0007, mitre_tactic_name Discovery, mitre_technique_id T1087_002, mitre_technique_name Account_Discovery_Domain_Account; sid:3321361; rev:9; classtype:attempted-recon;)

Metadata

created at2024_08_29
updated at2024_10_02
signature severityMajor
attack targetServer_Endpoint
mitre tactic idTA0007
mitre tactic nameDiscovery
mitre technique idT1087_002
mitre technique nameAccount_Discovery_Domain_Account

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!