From ec2cd5dd8092cde814253fe127bc0fb0f33bd218 Mon Sep 17 00:00:00 2001 From: Steven Dick <38897662+nterl0k@users.noreply.github.com> Date: Tue, 7 Jan 2025 15:52:52 -0500 Subject: [PATCH] Update detections/endpoint/windows_system_remote_discovery_with_query.yml Good suggestion Co-authored-by: Nasreddine Bencherchali --- .../endpoint/windows_system_remote_discovery_with_query.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/detections/endpoint/windows_system_remote_discovery_with_query.yml b/detections/endpoint/windows_system_remote_discovery_with_query.yml index 7e021937b8..1fd676d28e 100644 --- a/detections/endpoint/windows_system_remote_discovery_with_query.yml +++ b/detections/endpoint/windows_system_remote_discovery_with_query.yml @@ -4,7 +4,8 @@ version: 1 date: '2025-01-06' author: Steven Dick status: production -type: TTP +type: Anomaly + description: The following analytic detects the execution of `query.exe` with command-line arguments aimed at discovering data on remote devices. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as adversaries may use `query.exe` to gain situational awareness and perform Active Directory discovery on compromised endpoints. If confirmed malicious, this behavior could allow attackers to identify various details about a system, aiding in further lateral movement and privilege escalation within the network. data_source: - Sysmon Event ID 1