Defender-IdentityQueryEvents

ActionTypeTitleSampleRule
anyIdentity query activityNN
DNS queryDNS queryNN
LDAP queryLDAP queryNY
LdapQueryLdap queryNN
SAMR querySAMR queryNN

any: Identity query activity

#
Table
IdentityQueryEvents

DNS query

#
Table
IdentityQueryEvents

LDAP query

#
Table
IdentityQueryEvents

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

  • Suspicious LDAP Queries from Information Gathering Tools source: This rule detects usage of LDAP information gathering tools such as BloodHound, SharpHound or potential custom tools mimicking the behavior of the legitimate tool ADExplorer from Sysinternals. The rule detects tool-specific LDAP queries and also contains a custom "Signature" field, providing information about the exact tool that most probably created the detected LDAP query.T1087, T1087.002, T1482

LdapQuery: Ldap query

#
Table
IdentityQueryEvents

SAMR query

#
Table
IdentityQueryEvents

References #