Meta tags:
Headings (most frequently used words):
account, discovery, domain, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques, of,
Text of the page (most frequently used words):
#domain (83), retrieved (81), the (71), and (50), net (35), has (34), accounts (34), group (30), user (28), 2020 (27), 2022 (27), account (26), can (25), used (23), 2024 (22), may (20), enumerate (20), information (19), march (18), threat (17), april (17), october (16), 2023 (15), july (15), directory (14), users (14), december (13), 2025 (13), september (13), operation (13), active (13), from (12), february (12), august (12), all (11), june (11), for (11), 2026 (10), att (10), 2017 (10), team (10), 2016 (10), microsoft (10), with (10), commands (10), discovery (10), administrator (10), use (9), 2021 (9), ransomware (9), targets (9), 2019 (9), admins (9), get (9), victim (9), enterprise (8), actor (8), january (8), november (8), attacks (8), 2018 (8), identify (8), groups (7), techniques (7), research (7), spider (7), about (7), windows (7), tools (7), admin (7), name (7), t1087 (7), data (6), version (6), new (6), targeted (6), using (6), tool (6), exe (6), powershell (6), ldap (6), local (6), ics (5), mobile (5), none (5), system (5), cyber (5), targeting (5), intelligence (5), storm (5), through (5), apt41 (5), dsquery (5), enumeration (5), during (5), query (5), adfind (5), such (5), mitre (4), detection (4), sub (4), bronze (4), government (4), organizations (4), actors (4), cloud (4), response (4), services (4), scattered (4), redcurl (4), against (4), campaign (4), icedid (4), malware (4), fin7 (4), fin6 (4), queries (4), names (4), run (4), dom (4), ps1 (4), which (4), including (4), are (3), reference (3), software (3), cti (3), components (3), mitigations (3), defenses (3), tactics (3), intrusion (3), counter (3), cyberespionage (3), state (3), valak (3), toddycat (3), sykipot (3), stuxnet (3), 0501 (3), environments (3), cisa (3), sorefang (3), silenttrinity (3), incident (3), crowdstrike (3), rustywater (3), qilin (3), attack (3), multiple (3), middle (3), east (3), poshc2 (3), analysis (3), poseidon (3), security (3), wocao (3), hidden (3), cuckoobees (3), oilrig (3), mustang (3), panda (3), muddywater (3), apt (3), lotus (3), blossom (3), latrodectus (3), lapsus (3), lamehug (3), ke3chang (3), inc (3), ransom (3), iceapple (3), fin13 (3), other (3), command (3), chimera (3), via (3), brute (3), ratel (3), cobalt (3), strike (3), butler (3), administrative (3), bloodhound (3), blackcat (3), job (3), blackbyte (3), ryuk (3), bankshot (3), bazar (3), non (3), description (3), collect (3), wizard (3), compromised (3), utilized (3), environment (3), ability (3), list (3), machine (3), network (3), obtain (3), built (3), service (3), 002 (3), corporation (2), domains (2), resources (2), campaigns (2), analytics (2), strategies (2), assets (2), matrices (2), core (2), objects (2), running (2), application (2), unit (2), china (2), sponsored (2), check (2), more (2), 2011 (2), agencies (2), secureworks (2), modules (2), help (2), adversary (2), operations (2), across (2), industries (2), destruction (2), advisory (2), analyzing (2), implant (2), pentest (2), uncovering (2), server (2), global (2), espionage (2), one (2), hacking (2), cybereason (2), falcone (2), operating (2), systems (2), asian (2), earth (2), hunter (2), cert (2), brown (2), mstic (2), defender (2), 2014 (2), profile (2), dfir (2), follow (2), crime (2), financial (2), theft (2), stage (2), mike (2), this (2), infected (2), anchor (2), key (2), when (2), red (2), being (2), early (2), bumblebee (2), loader (2), credential (2), dscacheutil (2), endpoints (2), ldapsearch (2), platforms (2), analytic (2), enumerated (2), configuration (2), policies (2), also (2), volt (2), typhoon (2), adrecon (2), void (2), manticore (2), turla (2), display (2), permissions (2), membership (2), localgroup (2), administrators (2), enumerates (2), 1811 (2), discover (2), adgroupmember (2), aduser (2), solarwinds (2), compromise (2), retrieve (2), sandworm (2), cmdlets (2), powruner (2), osinfo (2), dream (2), gather (2), cmd (2), mirrorface (2), mgbot (2), csvde (2), export (2), menupass (2), associated (2), specific (2), module (2), fox (2), kitten (2), principal (2), within (2), scripts (2), vbs (2), empire (2), dusttrap (2), dragonfly (2), crackmapexec (2), determine (2), boombox (2), linux (2), macos (2), technique (2), adversaries (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, ucf, must, require, username, password, elevate, shilko, fin12, prolific, that, aggressively, pursued, healthcare, chinese, silhouette, defense, nsa, people, republic, living, off, land, evade, point, handala, hack, unveiling, modus, operandi, salem, than, meets, eye, faou, agent, btz, comrat, ten, year, journey, dedola, keep, calm, logs, blasco, another, sample, likely, federal, nicolas, falliere, liam, murchu, eric, chien, w32, dossier, misusing, quick, assist, social, engineering, leading, expanding, hybrid, mar, 10296782, ctu, iron, ritual, salvati, mandiant, desk, hypervisor, defending, your, vmware, vsphere, estate, unc3944, observes, escalate, octo, tempest, crosses, boundaries, facilitate, extortion, encryption, cybersecurity, aa23, 320a, cherepanov, rise, telebots, disruptive, killdisk, awasthi, reborn, rust, muddy, water, evolves, tooling, awakening, you, didn, know, takeda, methods, exposed, cases, sardiwal, apt34, suspected, iranian, cve, 11882, exploit, nettitude, python, kaspersky, lab, boutique, specializing, symantec, buckeye, shifts, gaze, hong, kong, dantzig, schamper, shining, light, breitenbacher, osis, ter, ception, european, aerospace, military, companies, nocturnus, deep, dive, into, stealthy, winnti, lee, saudi, arabian, deliver, helminth, backdoor, lior, rochberger, tom, fakterman, robert, southeast, linked, stately, taurus, aka, peretz, theck, vetala, continues, target, trend, micro, spot, difference, kasha, lodeinfo, correlation, apt10, umbrella, daggerfly, telecoms, company, africa, pwc, bae, hopper, technical, annex, symntec, billbug, authority, countries, joey, chen, cisco, talos, different, versions, sagerunex, stepanic, bousseaden, spring, cleaning, potential, replacement, recent, procedures, dart, m365, dev, 0537, criminal, exfiltration, simonovich, cato, ctrl, first, known, llm, powered, links, apt28, fancy, bear, villeneuve, bennett, moran, haq, scott, geers, ministries, foreign, affairs, socradar, dark, web, quantum, kessem, banking, trojan, discovered, ibm, force, novel, internet, iis, post, exploitation, framework, iran, based, exploits, vpn, vulnerabilities, blackberry, automotive, industry, fireeye, money, dissecting, sygnia, tg2003, elephant, beetle, organized, cybercriminal, focused, mexico, lyceum, takes, center, schroeder, warner, nelson, github, powershellempire, stokkel, arisen, dust, rufus, van, douglas, bienstock, geoff, ackerman, john, wolfram, does, look, summary, governments, alert, ta18, 074a, russian, activity, energy, critical, infrastructure, sectors, byt3bl33d3r, smb, dahan, dropping, trickbot, infection, jansen, abusing, fly, under, radar, cycraft, skeleton, taiwan, semiconductor, vendors, kenefick, black, basta, gang, infiltrates, networks, qakbot, harbison, renals, brutal, teaming, abused, malicious, japanese, enterprises, breaking, down, nobelium, latest, toolset, labs, rescue, many, lives, five, day, case, study, report, return, pantazopoulos, depth, team9, family, sherstobitoff, cobra, turkish, sector, nikita, rostovcev, world, tour, tight, schedule, kamble, rapidly, assuming, central, position, ecosystem, high, road, control, goody, nasty, trick, business, disruption, mckeague, pick, six, intercepting, recently, tied, lockergoga, brian, donohue, katie, nickels, paul, michaud, adina, bodkins, taylor, chapman, tony, lambert, jeff, felling, kyle, rainey, haag, matt, graeber, aaron, didier, start, how, hospital, thwarted, outbreak, bird, catches, wormhole, observations, stellarparticle, references, dscl, an0365, samba, wbinfo, winbindd, lookups, an0364, wmi, controllers, an0363, det0129, strategy, prevent, elevating, uac, since, lead, disclosure, registry, located, disabled, gpo, computer, templates, interface, elevation, hklm, currentversion, credui, enumerateadministrators, m1028, mitigation, identified, leveraged, cmdlet, adcomputer, g0102, g1017, g1055, s0476, g0010, g1022, s0018, s0603, performed, intrusions, g1046, obfuscated, reconnaissance, obfs, recon, g1053, s0516, exectuing, apt29, c0024, namespaces, accesscontrol, s0692, legitimate, g1015, discovering, usernames, listed, g0034, gathered, s9037, collected, sysinternal, adexplorer, functionality, g1039, s1242, series, s0184, s0378, searches, both, g0033, s0165, c0014, queried, servers, employees, lazarus, c0022, dsget, c0012, listings, exchange, trusted, subsystem, g0049, flag, manipulate, current, s0039, g0129, g0069, native, g1054, includes, collecting, s1146, administration, g0045, machines, make, g0030, system32, s1160, explorer, g1004, s9035, performs, redacted, g0004, scanned, g1032, additional, infect, s0483, querier, perform, authenticated, requests, s1022, softerra, browser, browse, documentation, g0117, script, 3cf9, executable, wstaskload, administrations, executing, line, g0046, metasploit, ntdsgrab, copy, database, psexec, g0037, utilizing, following, queryspn, getuserspns, g1016, acquire, s0363, s1159, s0105, batch, controller, g0035, s0488, s0154, g0114, s1063, g0060, execute, distinguished, sam, s0635, identification, s0521, utilize, s1068, g1043, s0534, gathers, process, monitoring, s0239, g0096, s0552, procedure, examples, live, permalink, last, modified, created, extrahop, miriam, wiesner, miriamxyra, contributors, tactic, utility, members, attempt, listing, exist, aid, behavior, possess, particular, privileges, 004, email, 003, 001, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, council, learn, started, detections,
Text of the page (random words):
te domain accounts 11 s1068 blackcat blackcat can utilize net use commands to identify domain users 12 s0521 bloodhound bloodhound can collect information about domain users including identification of domain admin accounts 13 s0635 boombox boombox has the ability to execute an ldap query to enumerate the distinguished name sam account name and display name for all domain users 14 g0060 bronze butler bronze butler has used net user domain to identify account information 15 s1063 brute ratel c4 brute ratel c4 can use ldap queries net group domain admins domain and net user domain for discovery 16 17 g0114 chimera chimera has has used net user dom and net user administrator to enumerate domain accounts including administrator accounts 18 19 s0154 cobalt strike cobalt strike can determine if the user on an infected machine is in the admin or domain admin group 20 s0488 crackmapexec crackmapexec can enumerate the domain user accounts on a targeted system 21 g0035 dragonfly dragonfly has used batch scripts to enumerate users on a victim domain controller 22 s0105 dsquery dsquery can be used to gather information on user accounts within a domain 23 24 s1159 dusttrap dusttrap can enumerate domain accounts 25 s0363 empire empire can acquire local and domain user account information 26 27 g1016 fin13 fin13 can identify user accounts associated with a service principal name and query service principal names within the domain by utilizing the following scripts getuserspns vbs and queryspn vbs 28 29 g0037 fin6 fin6 has used metasploit s psexec ntdsgrab module to obtain a copy of the victim s active directory database 30 g0046 fin7 fin7 has used the powershell script 3cf9 ps1 and the executable wstaskload to enumerate domain administrations by executing net group domain admins domain 31 fin7 has also used csvde exe which is a built in windows command line tool to export active directory information g0117 fox kitten fox kitten has used the softerra ldap browser to browse documentation on service accounts 32 s1022 iceapple the iceapple active directory querier module can perform authenticated requests against an active directory server 33 s0483 icedid icedid can query ldap and can use built in net commands to identify additional users on the network to infect 34 35 g1032 inc ransom inc ransom has scanned for domain admin accounts in compromised environments 36 g0004 ke3chang ke3chang performs account discovery using commands such as net localgroup administrators and net group redacted domain on specific permissions groups 37 s9035 lamehug lamehug can use dsquery to enumerate domain user information 38 g1004 lapsus lapsus has used the ad explorer tool to enumerate users on a victim s network 39 40 s1160 latrodectus latrodectus can run c windows system32 cmd exe c net group domain admins domain to identify domain administrator accounts 41 g0030 lotus blossom lotus blossom has used net commands and tools such as adfind to profile domain accounts associated with victim machines and make active directory queries 42 43 g0045 menupass menupass has used the microsoft administration tool csvde exe to export active directory data 44 s1146 mgbot mgbot includes modules for collecting information on active directory domain accounts 45 g1054 mirrorface mirrorface has used native windows tools to obtain domain user information 46 g0069 muddywater muddywater has used cmd exe net user domain to enumerate domain users 47 g0129 mustang panda mustang panda has utilized adfind to identify domain users 48 s0039 net net commands used with the domain flag can be used to gather information about and manipulate user accounts on the current domain 49 g0049 oilrig oilrig has run net user net user domain net group domain admins domain and net group exchange trusted subsystem domain to get account listings on a victim 50 c0012 operation cuckoobees during operation cuckoobees the threat actors used the dsquery and dsget commands to get domain environment information and to query users in administrative groups 51 c0022 operation dream job during operation dream job lazarus group queried compromised victim s active directory servers to obtain the list of employees including administrator accounts 52 c0014 operation wocao during operation wocao threat actors used the net command to retrieve information about domain accounts 53 s0165 osinfo osinfo enumerates local and domain users 54 g0033 poseidon group poseidon group searches for administrator accounts on both the local victim machine and the network 55 s0378 poshc2 poshc2 can enumerate local and domain user account information 56 s0184 powruner powruner may collect user account information by running net user domain or a series of other commands on a victim 57 s1242 qilin qilin can use powershell cmdlets to enumerate domain users 58 g1039 redcurl redcurl has collected information about domain accounts using sysinternal s adexplorer functionality 59 60 s9037 rustywater rustywater has gathered the domain membership of the victim machine s user 61 g0034 sandworm team sandworm team has used a tool to query active directory using ldap discovering information about usernames listed in ad 62 g1015 scattered spider scattered spider has enumerated legitimate domain accounts which are used in the targeted environment 63 64 65 66 s0692 silenttrinity silenttrinity can use system security accesscontrol namespaces to retrieve domain user information 67 c0024 solarwinds compromise during the solarwinds compromise apt29 used powershell to discover domain accounts by exectuing get aduser and get adgroupmember 1 68 s0516 sorefang sorefang can enumerate domain accounts via net exe user domain 69 g1053 storm 0501 storm 0501 has utilized an obfuscated version of the active directory reconnaissance tool adrecon ps1 obfs ps1 or recon ps1 to discover domain accounts 70 g1046 storm 1811 storm 1811 has performed domain account enumeration during intrusions 71 s0603 stuxnet stuxnet enumerates user accounts of the domain 72 s0018 sykipot sykipot may use net group domain admins domain to display accounts in the domain admins permissions group and net localgroup administrators to list local system administrator group membership 73 g1022 toddycat toddycat has run net user user dom for account discovery 74 g0010 turla turla has used net user domain to enumerate domain accounts 75 s0476 valak valak has the ability to enumerate domain admin accounts 76 g1055 void manticore void manticore has utilized adrecon to enumerate the active directory environment 77 g1017 volt typhoon volt typhoon has run net group dom and net group domain admins dom in compromised environments for account discovery 78 79 g0102 wizard spider wizard spider has identified domain admins through the use of net group domain admins domain wizard spider has also leveraged the powershell cmdlet get adcomputer to collect account names from active directory data 10 80 mitigations id mitigation description m1028 operating system configuration prevent administrator accounts from being enumerated when an application is elevating through uac since it can lead to the disclosure of account names the registry key is located at hklm software microsoft windows currentversion policies credui enumerateadministrators it can be disabled through gpo computer configuration policies administrative templates windows components credential user interface enumerate administrator accounts on elevation 81 detection strategy id name analytic id analytic description det0129 domain account enumeration across platforms an0363 adversary enumeration of domain accounts using net exe powershell wmi or ldap queries from non domain controllers or non admin endpoints an0364 domain account enumeration using ldapsearch samba tools e g wbinfo u or winbindd lookups an0365 domain group and user enumeration via dscl or dscacheutil or queries to directory services from non admin endpoints references crowdstrike 2022 january 27 early bird catches the wormhole observations from the stellarparticle campaign retrieved february 7 2022 brian donohue katie nickels paul michaud adina bodkins taylor chapman tony lambert jeff felling kyle rainey mike haag matt graeber aaron didier 2020 october 29 a bazar start how one hospital thwarted a ryuk ransomware outbreak retrieved october 30 2020 mckeague b et al 2019 april 5 pick six intercepting a fin6 intrusion an actor recently tied to ryuk and lockergoga ransomware retrieved april 17 2019 goody k et al 2019 january 11 a nasty trick from credential theft malware to business disruption retrieved may 12 2020 cybereason 2022 august 17 bumblebee loader the high road to enterprise domain control retrieved august 29 2022 kamble v 2022 june 28 bumblebee new loader rapidly assuming central position in cyber crime ecosystem retrieved august 24 2022 nikita rostovcev 2022 august 18 apt41 world tour 2021 on a tight schedule retrieved february 22 2024 sherstobitoff r 2018 march 08 hidden cobra targets turkish financial sector with new bankshot implant retrieved may 18 2018 pantazopoulos n 2020 june 2 in depth analysis of the new team9 malware family retrieved december 1 2020 the dfir report 2020 october 8 ryuk s return retrieved october 9 2020 microsoft incident response 2023 july 6 the five day job a blackbyte ransomware intrusion case study retrieved december 16 2024 microsoft defender threat intelligence 2022 june 13 the many lives of blackcat ransomware retrieved december 20 2022 red team labs 2018 april 24 hidden administrative accounts bloodhound to the rescue retrieved october 28 2020 mstic 2021 may 28 breaking down nobelium s latest early stage toolset retrieved august 4 2021 counter threat unit research team 2017 october 12 bronze butler targets japanese enterprises retrieved january 4 2018 harbison m and renals p 2022 july 5 when pentest tools go brutal red teaming tool being abused by malicious actors retrieved february 1 2023 kenefick i et al 2022 october 12 black basta ransomware gang infiltrates networks via qakbot brute ratel and cobalt strike retrieved february 6 2023 cycraft 2020 april 15 apt group chimera apt operation skeleton key targets taiwan semiconductor vendors retrieved august 24 2020 jansen w 2021 january 12 abusing cloud services to fly under the radar retrieved september 12 2024 dahan a et al 2019 december 11 dropping anchor from a trickbot infection to the discovery of the anchor malware retrieved september 10 2020 byt3bl33d3r 2018 september 8 smb command reference retrieved july 17 2020 us cert 2018 march 16 alert ta18 074a russian government cyber activity targeting energy and other critical infrastructure sectors retrieved june 6 2018 microsoft n d dsquery retrieved april 18 2016 rufus brown van ta douglas bienstock geoff ackerman john wolfram 2022 march 8 does this look infected a summary of apt41 targeting u s state governments retrieved july 8 2022 mike stokkel et al 2024 july 18 apt41 has arisen from the dust retrieved september 16 2024 schroeder w warner j nelson m n d github powershellempire retrieved april 28 2016 secureworks 2019 august 27 lyceum takes center stage in middle east campaign retrieved 2019 11 19 ta v et al 2022 august 8 fin13 a cybercriminal threat actor focused on mexico retrieved february 9 2023 sygnia incident response team 2022 january 5 tg2003 elephant beetle uncovering an organized financial theft operation retrieved february 9 2023 fireeye threat intelligence 2016 april follow the money dissecting the operations of the cyber crime group fin6 retrieved november 17 2024 the blackberry research and intelligence team 2024 april 17 threat group fin7 targets the u s automotive industry retrieved may 1 2025 cisa 2020 september 15 iran based threat actor exploits vpn vulnerabilities retrieved december 21 2020 crowdstrike 2022 may iceapple a novel internet information services iis post exploitation framework retrieved june 27 2022 kessem l et al 2017 november 13 new banking trojan icedid discovered by ibm x force research retrieved july 14 2020 dfir 2022 april 25 quantum ransomware retrieved july 26 2024 socradar 2024 january 24 dark web profile inc ransom retrieved june 5 2024 villeneuve n bennett j t moran n haq t scott m geers k 2014 operation ke3chang targeted attacks against ministries of foreign affairs retrieved november 12 2014 simonovich v 2025 july 23 cato ctrl threat research analyzing lamehug first known llm powered malware with links to apt28 fancy bear retrieved april 21 2026 mstic dart m365 defender 2022 march 24 dev 0537 criminal actor targeting organizations for data exfiltration and destruction retrieved may 17 2022 brown d et al 2022 april 28 lapsus recent techniques tactics and procedures retrieved december 22 2022 stepanic d and bousseaden s 2024 may 15 spring cleaning with latrodectus a potential replacement for icedid retrieved september 13 2024 joey chen cisco talos 2025 february 27 lotus blossom espionage group targets multiple industries with different versions of sagerunex and hacking tools retrieved march 15 2025 symntec threat hunter team 2022 november 12 billbug state sponsored actor targets cert authority government agencies in multiple asian countries retrieved march 15 2025 pwc and bae systems 2017 april operation cloud hopper technical annex retrieved april 13 2017 threat hunter team 2023 april 20 daggerfly apt actor targets telecoms company in africa retrieved july 25 2024 trend micro 2024 november 19 spot the difference earth kasha s new lodeinfo campaign and the correlation analysis with the apt10 umbrella retrieved april 17 2026 peretz a and theck e 2021 march 5 earth vetala muddywater continues to target organizations in the middle east retrieved march 18 2021 lior rochberger tom fakterman robert falcone 2023 september 22 cyberespionage attacks against southeast asian government linked to stately taurus aka mustang panda retrieved september 9 2025 microsoft 2017 february 14 net commands on windows operating systems retrieved march 19 2020 falcone r and lee b 2016 may 26 the oilrig campaign attacks on saudi arabian organizations deliver helminth backdoor retrieved may 3 2017 cybereason nocturnus 2022 may 4 operation cuckoobees deep dive into stealthy winnti techniques retrieved september 22 2022 breitenbacher d and osis k 2020 june 17 operation in ter ception targeted attacks against european aerospace and military companies retrieved december 20 2021 dantzig m v schamper e 2019 december 19 operation wocao shining a light on one of china s hidden hacking groups retrieved october 8 2020 symantec security response 2016 september 6 buckeye cyberespionage group shifts gaze from us to hong kong retrieved september 26 2016 kaspersky lab s global research and analysis team 2016 february 9 poseidon group a targeted attack boutique specializing in global cyber espionage retrieved march 16 2016 nettitude 2018 july 23 python server for poshc2 retrieved april 23 2019 sardiwal m et al 2017 december 7 new targeted att...
|