Remote System Discovery T1018

Tactic: Discovery

Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, net view using Net, or, on ESXi servers, `esxcli network diag ping`.

Events covered

19 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 86 rules share fields, values, and exclusions.

Fields filtered most (57 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine32contains 23, regex_match 7, in 2, eq 1, is_not_null 1 10., 127., 169.254., oudmp , (?i)(objectcategory|trustdmp|member\s(.*)?-list)
EventID25eq 254104, 4688, 1, 4103
process_name24eq 16, in 4, regex_match 3, wildcard 2dsquery.exe, powershell.exe, (?i)nslookup.exe, arp.exe, dsget.exe
OriginalFileName14eq 13, in 1net.exe, net1.exe, adfind.exe, dsquery.exe, nltestrk.exe
Image12ends_with 11, eq 1/arp, /ping, \adfind.exe, \net.exe, \net1.exe
EventType11contains 4, eq 4, in 3exec, connectionevent, exec_event, executed, connection_attempted
ScriptBlockText11contains 10, in 1, match 1get-domaincomputer, get-adcomputer, get-netcomputer, *findall()*, *findone()*
event.type11eq 11start
host.os.type11eq 11
Type8eq 8
event_count7gt 70, 100, 2
process.args7eq 5, contains 2, wildcard 2, in 1, starts_with 1(objectcategory=attributeschema), (objectcategory=computer), (objectcategory=group), *.cluster.local, *.svc
EventOriginalType5contains 4, ne 11370, policy violation, suspicious activity, suspicious file transfer, threat
ParentImage4contains 3, ends_with 3-tomcat-, \caddy.exe, \httpd.exe, \w3wp.exe, cmd.exe
sourcetype3eq 3cisco:sfw:estreamer, cisco:ios

Top indicator values (530 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventIDeq
4104
12269
EventIDeq
4688
8317
EventIDeq
1
4241
EventIDeq
4103
4105
event.typeeq
start
111078
OriginalFileNameeq
net.exe
531
OriginalFileNameeq
net1.exe
544
OriginalFileNameeq
adfind.exe
34
CommandLinecontains
adinfo
44
CommandLinecontains
computers_pwdnotreqd
44
CommandLinecontains
dcmodes
44
CommandLinecontains
domainlist
44
CommandLinecontains
trustdmp
44
CommandLinecontains
objectcategory=
33
CommandLinecontains
-w hidden
25
CommandLinecontains
10.
23
CommandLinecontains
127.
22
CommandLinecontains
169.254.
22
CommandLinecontains
172.16.
22
CommandLinecontains
172.17.
22
CommandLinecontains
172.18.
22
CommandLinecontains
172.19.
22
process_nameeq
dsquery.exe
412
process_nameeq
nltest.exe
411
process_nameeq
powershell.exe
4184
process_nameeq
net.exe
328
process_nameeq
net1.exe
339
ParentImageends_with
\w3wp.exe
312
ScriptBlockTextcontains
get-domaincomputer
33
event_countgt
0
33

Exclusions (65 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
user.idin
S-1-5-18
2
user.idin
S-1-5-19
2
user.idin
S-1-5-20
2
CommandLinecontains
\\\\
1
CommandLineeq
net view \\localhost
1
CurrentDirectoryin
/opt/SolarWinds/Agent/bin/Plugins/SCM
1
CurrentDirectoryin
/opt/cohesityagent/software/crux/bin
1
Imageends_with
\adfind.exe
1
Imagein
/app/extra/chrome
1
Imagein
/usr/bin/prometheus
1
Imagein
/usr/lib/virtualbox/vboxheadless
1
Imagein
/usr/local/bin/prometheus
1
Imagestarts_with
/opt/gitlab/
1
Imagestarts_with
/opt/google/chrome/chrome
1
Imagestarts_with
/opt/rumble/bin/rumble-agent
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 18 rules

Elastic 15 rules

Splunk 42 rules

Kusto 10 rules

Panther 1 rule