Sub-technique of T1069 Permission Groups Discovery.View on attack.mitre.org
Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.
Commands such as net group /domain of the Net utility, dscacheutil -q group on macOS, and ldapsearch on Linux can list domain-level groups.
Rules on DetectionCode tagged with T1069.002.
| Rule | Level | Log source |
|---|---|---|
| BloodHound Collection Files | high | windows / file_event |
| HackTool - Bloodhound/Sharphound Execution | high | windows / process_creation |
| HackTool - SharpView Execution | high | windows / process_creation |
| Malicious PowerShell Commandlets - PoshModule | high | windows / ps_module |
| Malicious PowerShell Commandlets - ProcessCreation | high | windows / process_creation |
| Malicious PowerShell Commandlets - ScriptBlock | high | windows / ps_script |
| PUA - AdFind Suspicious Execution | high | windows / process_creation |
| Reconnaissance Activity | high | windows / NULL |
| Renamed AdFind Execution | high | windows / process_creation |
| Suspicious Active Directory Database Snapshot Via ADExplorer | high | windows / process_creation |
| Active Directory Database Snapshot Via ADExplorer | medium | windows / process_creation |
| ADExplorer Writing Complete AD Snapshot Into .dat File | medium | windows / file_event |
| Potential Active Directory Reconnaissance/Enumeration Via LDAP | medium | windows / NULL |
| Active Directory Group Enumeration With Get-AdGroup | low | windows / ps_script |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect AzureHound Command-Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect AzureHound File Modifications | TTP | NULL | Sysmon EventID 11 |
| Detect SharpHound Command-Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect SharpHound File Modifications | TTP | NULL | Sysmon EventID 11 |
| Detect SharpHound Usage | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Domain Group Discovery with Adsisearcher | TTP | NULL | Powershell Script Block Logging 4104 |
| Domain Group Discovery With Dsquery | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Domain Group Discovery With Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Domain Group Discovery With Wmic | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Elevated Group Discovery With Net | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Elevated Group Discovery with PowerView | Hunting | NULL | Powershell Script Block Logging 4104 |
| Elevated Group Discovery With Wmic | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetAdGroup with PowerShell | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetAdGroup with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 |
| GetDomainGroup with PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetDomainGroup with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 |
| GetWmiObject Ds Group with PowerShell | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetWmiObject Ds Group with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 |
| Network Traffic to Active Directory Web Services Protocol | Hunting | NULL | Sysmon EventID 3 |
| Windows Group Discovery Via Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Ldifde Directory Object Behavior | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Sensitive Group Discovery With Net | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows SOAPHound Binary Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupDragonfly | Dragonfly has used batch scripts to enumerate administrators and users in the domain. |
| GroupFIN7 | FIN7 has used the command `net group "domain admins" /domain` to enumerate domain groups. |
| GroupINC Ransom | INC Ransom has enumerated domain groups on targeted hosts. |
| GroupInception | Inception has used specific malware modules to gather domain membership. |
| GroupKe3chang | Ke3chang performs discovery of permission groups |
| GroupLAPSUS$ | LAPSUS$ has used the AD Explorer tool to enumerate groups on a victim's network. |
| GroupMedusa Group | Medusa Group has utilized the `net group` command to query domain groups within the victim environment. |
| GroupMustang Panda | Mustang Panda has leveraged AdFind to enumerate domain groups. |
| Used by | Procedure example |
|---|---|
| ToolAdFind | AdFind can enumerate domain groups. |
| MalwareBADHATCH | BADHATCH can use `net.exe group "domain admins" /domain` to identify Domain Administrators. |
| MalwareBlackCat | BlackCat can determine if a user on a compromised host has domain admin privileges. |
| ToolBloodHound | BloodHound can collect information about domain groups and members. |
| ToolBrute Ratel C4 | Brute Ratel C4 can use `net group` for discovery on targeted domains. |
| MalwareCobalt Strike | Cobalt Strike can identify targets by querying account groups on a domain contoller. |
| ToolCrackMapExec | CrackMapExec can gather the user accounts within domain groups. |
| Tooldsquery | dsquery can be used to gather information on permission groups within a domain. |
| Used by | Procedure example |
|---|---|
| CampaignC0015 | During C0015, the threat actors use the command `net group "domain admins" /dom` to enumerate domain groups. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used AdFind to enumerate domain groups. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.