Permission Groups Discovery T1069

Tactic: Discovery

Adversaries may attempt to discover group and permission settings. This information can help adversaries determine which user accounts and groups are available, the membership of users in particular groups, and which users and groups have elevated permissions.

Events covered

26 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 136 rules share fields, values, and exclusions.

Fields filtered most (135 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine39contains 27, regex_match 8, in 4, eq 1, wildcard 1(?i)\s+(localgroup|group(s?)\s+.*doma)|Get-AD(PrincipalGr..., group, group, oudmp , (?i)(objectcategory|trustdmp|member\s(.*)?-list)
process_name36eq 27, ends_with 3, in 3, regex_match 2, wildcard 2, contains 1powershell.exe, wmic.exe, \lsass.exe, cmd.exe, dscl
EventID24eq 244104, 4103, 4688, 1, 4662
OriginalFileName18eq 18net1.exe, net.exe, adexp, wmic.exe, adfind.exe
ScriptBlockText17contains 14, in 4, eq 1get-wmiobject, (objectcategory=group), *account operators*, *dns admins*, *domain admins*
host.os.type17eq 15, in 2
EventType16eq 8, in 7, contains 1exec, exec_event, ProcessRollup2, open, io.k8s.authorization.v1.selfsubjectaccessreviews.create
Image16ends_with 12, is_not_null 2, contains 1, eq 1\adexp.exe, \adexplorer.exe, \adexplorer64.exe, /cat, \net.exe
event.type15eq 14, in 1start, process_started
process.args11eq 6, in 4, contains 3, wildcard 3, starts_with 2-list, %appdata%, %homepath%, %localappdata%, (objectcategory=attributeschema)
data_stream.dataset10eq 9, in 1azure.aadgraphactivitylogs, azure.signinlogs, kubernetes.audit_logs, aws.cloudtrail, azure.activitylogs
process.Ext.api.name6eq 6ldap_search
process.Ext.api.parameters.search_filter6eq 4, wildcard 2, contains 1(&(objectCategory=group)(name=Domain Admins)), (&(objectCategory=user)(userAccountControl:1.2.840.113556..., (&(objectClass=group)(managedBy=?)(groupType:1.2.840.1135..., (&(objectClass=group)(managedBy=?)), (&(samAccountType=805306368)(|(homedirectory=?)(scriptpat...
ObjectType5eq 4, contains 1sam_group, sam_user, sam_alias, {bf967a9c-0de6-11d0-a285-00aa003049e2}
Payload5contains 5-f , -pr , add-exfiltration, add-persistence, add-regbackdoor

Top indicator values (1638 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventIDeq
4104
14269
EventIDeq
4103
5105
EventIDeq
4688
5317
EventIDeq
1
3241
event.typeeq
start
141078
EventTypein
exec
6201
EventTypein
exec_event
6149
EventTypein
ProcessRollup2
5117
EventTypein
executed
498
EventTypein
process_started
483
EventTypein
start
4163
OriginalFileNameeq
net1.exe
644
OriginalFileNameeq
net.exe
431
process.Ext.api.nameeq
ldap_search
614
CommandLinecontains
group
57
CommandLinecontains
adinfo
34
CommandLinecontains
computers_pwdnotreqd
34
CommandLinecontains
dcmodes
34
CommandLinecontains
domainlist
34
CommandLinecontains
trustdmp
34
SubjectUserNameends_with
$
55
process_nameeq
net1.exe
539
process_nameeq
powershell.exe
5184
process_nameeq
wmic.exe
466
ObjectNamestarts_with
S-1-5-21-
45
event.categoryeq
process
4142
CommandLineregex_match
(?i)\s+(localgroup|group(s?)\s+.*doma)|Get-AD(PrincipalGroupMembership|Group)...
33
EventTypeeq
exec
3576
Imageends_with
\adexp.exe
33
Imageends_with
\adexplorer.exe
34

Exclusions (213 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
SubjectUserNameends_with
$
6
Imagewildcard
?:\windows\adws\microsoft.activedirectory.webservices.exe
5
Imagewildcard
?:\program files\azure advanced threat protection sensor\*\microsoft.tri.sensor.exe
4
Imagewildcard
?:\windows\adfs\microsoft.identityserver.servicehost.exe
4
Imagewildcard
?:\windows\system32\lsass.exe
4
process.code_signature.trustedeq
true
3
user.ideq
s-1-5-18
2
user.idin
S-1-5-18
2
user.idin
S-1-5-19
2
user.idin
S-1-5-20
2
CallerProcessNameeq
-
1
CallerProcessNameeq
c:\windows\immersivecontrolpanel\systemsettings.exe
1
CallerProcessNameeq
c:\windows\system32\cloudexperiencehostbroker.exe
1
CallerProcessNameeq
c:\windows\system32\compattelrunner.exe
1
CallerProcessNameeq
c:\windows\system32\dfsrs.exe
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 35 rules

Elastic 39 rules

Splunk 50 rules

Kusto 10 rules

YARA-L 1 rule

Panther 1 rule