AD Privileged Users or Groups Reconnaissance

 Original Source: [Sigma source]
Title: AD Privileged Users or Groups Reconnaissance
Status: test
Description:Detect priv users or groups recon based on 4661 eventid and known privileged users or groups SIDs
References:
  -https://web.archive.org/web/20230329163438/https://blog.menasec.net/2019/02/threat-hunting-5-detecting-enumeration.html
Author: Samir Bousseaden
Date: 2019-04-03
modified:2022-07-13
Tags:
  • -'attack.discovery'
  • -'attack.t1087.002'
Logsource:
  • product: windows
  • service: security
  • definition: Requirements: enable Object Access SAM on your Domain Controllers
Detection:
  selection:
    EventID: '4661'
    ObjectType:
      -'SAM_USER'
      -'SAM_GROUP'

  selection_object:
    - ObjectName|endswith:
      - '-512'
      - '-502'
      - '-500'
      - '-505'
      - '-519'
      - '-520'
      - '-544'
      - '-551'
      - '-555'
ObjectName|contains:'admin'   filter:
    SubjectUserName|endswith: '$'
  condition:selection and selection_object and not filter
Falsepositives:
  -If source account name is not an admin then its super suspicious
Level: high