2023-08-25 19:10:12 +05:30
[ metadata ]
creation_date = "2023/08/23"
2025-11-10 16:03:39 +01:00
integration = [ "endpoint" , "auditd_manager" , "crowdstrike" ]
2023-08-25 19:10:12 +05:30
maturity = "production"
2025-11-10 16:03:39 +01:00
updated_date = "2025/10/17"
2023-08-25 19:10:12 +05:30
[ rule ]
author = [ "Elastic" ]
building_block_type = "default"
description = "" "
2024-03-07 12:35:33 +01:00
Identifies the execution of Linux built-in commands related to account or group enumeration. Adversaries may use account
and group information to orient themselves before deciding how to act.
" ""
2023-08-25 19:10:12 +05:30
from = "now-119m"
2025-11-10 16:03:39 +01:00
index = [ "logs-endpoint.events.*" , "endgame-*" , "auditbeat-*" , "logs-auditd_manager.auditd-*" , "logs-crowdstrike.fdr*" ]
2024-05-23 00:45:10 +05:30
interval = "60m"
2023-08-25 19:10:12 +05:30
language = "eql"
license = "Elastic License v2"
name = "Discovery of Domain Groups"
risk_score = 21
rule_id = "b92d5eae-70bb-4b66-be27-f98ba9d0ccdc"
severity = "low"
2024-03-07 12:35:33 +01:00
tags = [
2025-11-10 16:03:39 +01:00
"Domain: Endpoint" ,
"OS: Linux" ,
"Use Case: Threat Detection" ,
"Tactic: Discovery" ,
"Rule Type: BBR" ,
"Data Source: Elastic Defend" ,
"Data Source: Elastic Endgame" ,
"Data Source: Auditd Manager" ,
"Data Source: Crowdstrike" ,
2024-05-23 00:45:10 +05:30
]
2023-08-25 19:10:12 +05:30
timestamp_override = "event.ingested"
type = "eql"
2024-05-23 00:45:10 +05:30
2023-08-25 19:10:12 +05:30
query = '' '
2025-11-10 16:03:39 +01:00
process where host.os.type == "linux" and event.type == "start" and event.action in ("exec", "exec_event", "executed", "process_started", "ProcessRollup2")
2024-03-13 10:11:21 +01:00
and (
2024-03-07 12:35:33 +01:00
process.name in ("ldapsearch", "dscacheutil") or (process.name == "dscl" and process.args : "*-list*")
)
2023-08-25 19:10:12 +05:30
' ''
2024-05-23 00:45:10 +05:30
2023-08-25 19:10:12 +05:30
[ [ rule . threat ] ]
framework = "MITRE ATT&CK"
[ [ rule . threat . technique ] ]
id = "T1069"
name = "Permission Groups Discovery"
reference = "https://attack.mitre.org/techniques/T1069/"
2024-05-23 00:45:10 +05:30
2023-08-25 19:10:12 +05:30
[ rule . threat . tactic ]
id = "TA0007"
name = "Discovery"
reference = "https://attack.mitre.org/tactics/TA0007/"
2024-05-23 00:45:10 +05:30