🐾 - 🚨 Successful LDAP user object creation on 🪟 Active Directory - 🥷 Domain Account Creation - T1136.002

SID: 3321377Rev: 580 views
History
Sourcepawpatrules
CreatedOctober 2, 2024
UpdatedOctober 6, 2024
Classificationattempted-recon
alert tcp $HOME_NET 389 -> any any (msg:"🐾 - 🚨 Successful LDAP user object creation on 🪟 Active Directory - 🥷 Domain Account Creation - T1136.002"; flow:to_client, established; flowbits:isset,pptrls.ldapcreateuserad; content:"|69 84 00 00 00 07 0a 01 00 04 00 04 00|"; reference:url,https://attack.mitre.org/techniques/T1136/002/; reference:url,https://ldap3.readthedocs.io/en/latest/add.html; reference:url,https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42291; metadata:created_at 2024_10_02, updated_at 2024_10_06, signature_severity Major, attack_target Server_Endpoint, mitre_tactic_id TA0003, mitre_tactic_name Persistence, mitre_technique_id T1136_002, mitre_technique_name Create_Account_Domain_Account; sid:3321377; rev:5; classtype:attempted-recon;)

Metadata

created at2024_10_02
updated at2024_10_06
signature severityMajor
attack targetServer_Endpoint
mitre tactic idTA0003
mitre tactic namePersistence
mitre technique idT1136_002
mitre technique nameCreate_Account_Domain_Account

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!