Gather Victim Org Information T1591

Tactic: Reconnaissance

Adversaries may gather information about the victim's organization that can be used during targeting. Information about an organization may include a variety of details, including the names of divisions/departments, specifics of business operations, as well as the roles and responsibilities of key employees.

Authoring guide

These 5 rules share fields, values, and exclusions.

Fields filtered most (7 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
RatingDifferance2lt 20
auditType.action2eq 2user details export failed, user details export started, user details exported, user permissions export failed, user permissions export started
auditType.category2eq 2users and groups
CommadCount1ge 18
aws::userAgent1starts_with 1aws-cli
command1contains 1suspiciouscommands
percentage1ge 110

Top indicator values (12 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
RatingDifferancelt
0
22
auditType.categoryeq
users and groups
22
CommadCountge
8
1
auditType.actioneq
user details export failed
1
auditType.actioneq
user details export started
1
auditType.actioneq
user details exported
1
auditType.actioneq
user permissions export failed
1
auditType.actioneq
user permissions export started
1
auditType.actioneq
user permissions exported
1
aws::userAgentstarts_with
aws-cli
1
commandcontains
suspiciouscommands
1
percentagege
10
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 2 rules

Kusto 3 rules