Skip to the content.

back

Find sigma rule :x:

Attack: Permission Groups Discovery: Domain Groups

Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.

Commands such as net group /domain of the Net utility, dscacheutil -q group on macOS, and ldapsearch on Linux can list domain-level groups.

MITRE

Tactic

technique

Test : Active Directory Domain Search Using LDAP - Linux (Ubuntu)/macOS

OS

Description:

Output information from LDAPSearch. LDAP Password is the admin-user password on Active Directory

Executor

sh

Sigma Rule

back