T1018 Remote System Discovery
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as [Ping](https://attack.mitre.org/software/S0097), net view using…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Chopper Webshell Process Patternhightest · windows
- PUA - AdFind Suspicious Executionhightest · windows
- Renamed AdFind Executionhightest · windows
- Webshell Detection With Command Line Keywordshightest · windows
- Webshell Hacking Activity Patternshightest · windows
- HackTool - NetExec Executionhighexperimental · windows
- DirectorySearcher Powershell Exploitationmediumtest · windows
- Suspicious Scan Loop Networkmediumtest · windows
- Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlockmediumexperimental · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.