logo

How to hunt for reconnaissance

ID: e2bde1ad-f968-52ce-95d3-4128f2e0ccb7

STIX ID: report--e2bde1ad-f968-52ce-95d3-4128f2e0ccb7

Feed Name: Expel Blog

Date Published: 2018-08-02

Date Updated: 2026-04-27

Author: Alec Randazzo

...
...

This guide describes an EDR-based hunting technique to detect early-stage reconnaissance by threat actors in Windows environments. It provides Carbon Black and CrowdStrike query examples that capture common built-in Windows discovery utilities invoked via cmd.exe or powershell.exe, recommends filtering to cases where at least three such commands occur within a five-minute window to dramatically reduce false positives, and advises using process lineage for investigation and converting suspicious command-line patterns into EDR alerts to enable faster detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.