Log Enumeration T1654

Tactic: Discovery

Adversaries may enumerate system and service logs to find useful data. These logs may highlight various types of valuable insights for an adversary, such as user authentication records (Account Discovery), security or vulnerable software (Software Discovery), or hosts within a compromised network (Remote System Discovery).

Events covered

2 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 3 rules share fields, values, and exclusions.

Fields filtered most (12 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine1contains 1, in 1* qe *, * query-events *, *.readevent(*
EventType1eq 1DOWNLOAD
OriginalFileName1eq 1, in 1powershell.exe, powershell_ise.exe, pwsh.dll
component1eq 1jsonwebtoken
event.category1eq 1AUDIT_LOGS
event.errorcode1eq 1None
event.result1eq 1SUCCESS
event_message1starts_with 1validating token:
log_level1eq 1debug
process_name1eq 1, in 1powershell.exe, powershell_ise.exe, pwsh.exe
sourcetype1eq 1splunkd
token1ne 1none

Top indicator values (30 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
CommandLinecontains
eventcode
1
CommandLinecontains
ntevent
1
CommandLinecontains
win32_ntlogevent
13
CommandLinein
* qe *
1
CommandLinein
* query-events *
1
CommandLinein
*.readevent(*
1
CommandLinein
*eventlogquery*
1
CommandLinein
*eventquery*
1
CommandLinein
*get-eventlog*
1
CommandLinein
*get-winevent*
1
CommandLinein
*psloglist*
1
EventTypeeq
DOWNLOAD
1
OriginalFileNameeq
wevtutil.exe
17
OriginalFileNameeq
wmic.exe
180
OriginalFileNamein
powershell.exe
121
OriginalFileNamein
powershell_ise.exe
19
OriginalFileNamein
pwsh.dll
110
componenteq
jsonwebtoken
1
event.categoryeq
AUDIT_LOGS
1
event.errorcodeeq
None
110
event.resulteq
SUCCESS
110
event_messagestarts_with
validating token:
1
log_leveleq
debug
12
process_nameeq
wevtutil.exe
110
process_nameeq
wmic.exe
166
process_namein
powershell.exe
136
process_namein
powershell_ise.exe
110
process_namein
pwsh.exe
126
sourcetypeeq
splunkd
12
tokenne
none
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Splunk 2 rules

Panther 1 rule