Skip to content

Latest commit

 

History

History
42 lines (35 loc) · 1.48 KB

FIRST-S00028.md

File metadata and controls

42 lines (35 loc) · 1.48 KB

Rules: First Seen Common Windows Recon Commands From User

Description

Detects a set of commands often used in recon stages by different attack groups.

Additional Details

Detail Value
Type First Seen
Category Discovery
Apply Risk to Entities device_hostname, user_username
Signal Name First Seen Common Windows Recon Commands From User
Summary Expression Detected reconnaissance activity from user: {{user_username}} on host: {{device_hostname}}
Retention Window 7776000000
Baseline Window 1209600000
Baseline Type GLOBAL
Score/Severity Static: 2
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0007, _mitreAttackTechnique:T1018

Vendors and Products

Fields Used

Origin Field
Normalized Schema commandLine
Normalized Schema device_hostname
Normalized Schema listMatches
Normalized Schema lower
Normalized Schema parentBaseImage
Normalized Schema user_username