System Location Discovery T1614
Tactic: Discovery
Adversaries may gather information in an attempt to calculate the geographical location of a victim host. Adversaries may use the information from System Location Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Events covered
3 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 22 | DNSEvent (DNS query) |
| Security-Auditing | Event ID 4688 | A new process has been created. |
Authoring guide
These 6 rules share fields, values, and exclusions.
Fields filtered most (15 distinct)
These fields appear most often in rule filters.
Top indicator values (45 distinct)
These values appear most often in rule predicates.
Exclusions (30 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: Windows
Domain: Endpoint