1200KM / detection
T1087.002 Domain Account — Detection Rules
Detection workspace for T1087.002 Domain Account: 20 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Potential Active Directory Reconnaissance/Enumeration Via LDAP · test · medium · {"product":"windows","service":"ldap","definition":"Requirements: Microsoft-Windows-LDAP-Client/Debug ETW logging"}
- AD Privileged Users or Groups Reconnaissance · test · high · {"product":"windows","service":"security","definition":"Requirements: enable Object Access SAM on your Domain Controllers"}
- Potential AD User Enumeration From Non-Machine Account · test · medium · {"product":"windows","service":"security","definition":"Requirements: The \"Read all properties\" permission on the user object needs to be audited for the \"Everyone\" principal"}
- Reconnaissance Activity · test · high · {"product":"windows","service":"security","definition":"The volume of Event ID 4661 is high on Domain Controllers and therefore \"Audit SAM\" and \"Audit Kernel Object\" advanced audit policy settings are not configured in the recommendations for server systems"}
- BloodHound Collection Files · test · high · {"product":"windows","category":"file_event"}
- ADExplorer Writing Complete AD Snapshot Into .dat File · experimental · medium · {"category":"file_event","product":"windows"}
- Malicious PowerShell Commandlets - PoshModule · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Active Directory Computers Enumeration With Get-AdComputer · test · low · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Malicious PowerShell Commandlets - ScriptBlock · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Active Directory Structure Export Via Csvde.EXE · test · medium · {"category":"process_creation","product":"windows"}
- HackTool - Bloodhound/Sharphound Execution · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Group And Account Reconnaissance Activity Using Net.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Malicious PowerShell Commandlets - ProcessCreation · test · high · {"category":"process_creation","product":"windows"}
- PUA - Suspicious ActiveDirectory Enumeration Via AdFind.EXE · test · high · {"product":"windows","category":"process_creation"}
- PUA - AdFind.EXE Execution · experimental · medium · {"product":"windows","category":"process_creation"}
- PUA - AdFind Suspicious Execution · test · high · {"category":"process_creation","product":"windows"}
- Renamed AdFind Execution · test · high · {"category":"process_creation","product":"windows"}
- Active Directory Database Snapshot Via ADExplorer · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Active Directory Database Snapshot Via ADExplorer · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Use of PsLogList · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0129 Domain Account Enumeration Across Platforms
AN0363 Analytic 0363
Adversary enumeration of domain accounts using net.exe, PowerShell, WMI, or LDAP queries from non-domain controllers or non-admin endpoints.
AN0364 Analytic 0364
Domain account enumeration using ldapsearch, samba tools (e.g., 'wbinfo -u'), or winbindd lookups.
AN0365 Analytic 0365
Domain group and user enumeration via dscl or dscacheutil, or queries to directory services from non-admin endpoints.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- Turla · G0010
- Lotus Blossom · G0030
- Poseidon Group · G0033
- Sandworm Team · G0034
- Dragonfly · G0035
- FIN6 · G0037
- menuPass · G0045
- FIN7 · G0046
- OilRig · G0049
- BRONZE BUTLER · G0060
- MuddyWater · G0069
- APT41 · G0096
- Wizard Spider · G0102
- Chimera · G0114
- Fox Kitten · G0117
- Mustang Panda · G0129
- LAPSUS$ · G1004
- Scattered Spider · G1015
- FIN13 · G1016
- Volt Typhoon · G1017
- ToddyCat · G1022
- INC Ransom · G1032
- RedCurl · G1039
- BlackByte · G1043
- Storm-1811 · G1046
- Storm-0501 · G1053
- MirrorFace · G1054
- VOID MANTICORE · G1055
Existing anomaly research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.