Detection Playbook: Domain Groups (T1069.002)
Domain Groups enumeration (T1069.002) is the act of querying Active Directory or a domain controller to map out domain-level groups and their memberships. At…
Threat Intelligence for Every Defender
Daily MITRE ATT&CK-based detection playbooks covering common adversary techniques. Each playbook includes SIEM-agnostic detection logic and investigation and response guidance.
Domain Groups enumeration (T1069.002) is the act of querying Active Directory or a domain controller to map out domain-level groups and their memberships. At…
Domain Account Discovery (T1087.002) is a technique where adversaries enumerate domain user accounts and groups to map out the Active Directory environment. …
Network Service Discovery (T1046) is a reconnaissance technique where adversaries scan local and remote systems to enumerate running services, open ports, an…
Obfuscated Files or Information (T1027) describes the practice of encoding, encrypting, compressing, or otherwise obscuring malicious content to make it hard…
Regsvr32.exe is a legitimate Windows utility designed to register and unregister COM objects and DLLs. Attackers abuse it to execute malicious scripts or DLL…
Rundll32.exe is a legitimate Windows utility designed to load and execute functions exported from DLL files. Attackers abuse it to execute malicious payloads…
Pass the Hash (PtH) is a credential-based lateral movement technique where an attacker uses a captured NTLM password hash — rather than the plaintext passwor…
Kerberoasting is a credential theft technique in which an attacker with any valid domain account requests Kerberos Ticket-Granting Service (TGS) tickets for …
Password spraying is a credential access technique where an adversary attempts a single commonly used password — or a very short list — across a large number…
LSASS Memory dumping (T1003.001) is a credential theft technique where attackers extract authentication material — including NTLM hashes, Kerberos tickets, a…