How to hunt for reconnaissance
ID: e2bde1ad-f968-52ce-95d3-4128f2e0ccb7
STIX ID: report--e2bde1ad-f968-52ce-95d3-4128f2e0ccb7
Feed Name: Expel Blog
This guide describes an EDR-based hunting technique to detect early-stage reconnaissance by threat actors in Windows environments. It provides Carbon Black and CrowdStrike query examples that capture common built-in Windows discovery utilities invoked via cmd.exe or powershell.exe, recommends filtering to cases where at least three such commands occur within a five-minute window to dramatically reduce false positives, and advises using process lineage for investigation and converting suspicious command-line patterns into EDR alerts to enable faster detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
