Update detections/endpoint/windows_system_remote_discovery_with_query.yml

Good suggestion

Co-authored-by: Nasreddine Bencherchali <monsteroffire2@gmail.com>
This commit is contained in:
Steven Dick
2025-01-07 15:52:52 -05:00
committed by GitHub
parent 18cf044020
commit ec2cd5dd80
@@ -4,7 +4,8 @@ version: 1
date: '2025-01-06'
author: Steven Dick
status: production
type: TTP
type: Anomaly
description: The following analytic detects the execution of `query.exe` with command-line arguments aimed at discovering data on remote devices. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as adversaries may use `query.exe` to gain situational awareness and perform Active Directory discovery on compromised endpoints. If confirmed malicious, this behavior could allow attackers to identify various details about a system, aiding in further lateral movement and privilege escalation within the network.
data_source:
- Sysmon Event ID 1