Reconnaissance Activity

 Original Source: [Sigma source]
Title: Reconnaissance Activity
Status: test
Description:Detects activity as "net user administrator /domain" and "net group domain admins /domain"
References:
  -https://findingbad.blogspot.de/2017/01/hunting-what-does-it-look-like.html
Author: Florian Roth (Nextron Systems), Jack Croock (method), Jonhnathan Ribeiro (improvements), oscd.community
Date: 2017-03-07
modified:2022-08-22
Tags:
  • -'attack.discovery'
  • -'attack.t1087.002'
  • -'attack.t1069.002'
  • -'attack.s0039'
Logsource:
  • product: windows
  • service: security
  • definition: The volume of Event ID 4661 is high on Domain Controllers and therefore "Audit SAM" and "Audit Kernel Object" advanced audit policy settings are not configured in the recommendations for server systems
Detection:
  selection:
    EventID: '4661'
    AccessMask: '0x2d'
    ObjectType:
      -'SAM_USER'
      -'SAM_GROUP'

    ObjectName|startswith: 'S-1-5-21-'
    ObjectName|endswith:
      -'-500'
      -'-512'

  condition:selection
Falsepositives:
  -Administrator activity
Level: high