DirectorySearcher Powershell Exploitation (1f6399cf-2c80-4924-ace1-6fcff3393480)
Enumerates Active Directory to determine computers that are joined to the domain
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Remote System Discovery - T1018 (e358d692-23c0-4a31-9eb6-ecc13a8d7735) | Attack Pattern | DirectorySearcher Powershell Exploitation (1f6399cf-2c80-4924-ace1-6fcff3393480) | Sigma-Rules | 1 |