logo

Internal Reconnaissance in Domain Environments Detected by EDR

ID: 5d7eb76b-1ab0-5304-a0f2-ad2c8d61b2af

STIX ID: report--5d7eb76b-1ab0-5304-a0f2-ad2c8d61b2af

Feed Name: ASEC

Date Published: 2024-01-02

Date Updated: 2026-04-26

Author: ASEC

...
...

The report outlines common attacker reconnaissance and lateral movement techniques in Active Directory environments, detailing the use of port scanners, Windows net/PowerShell commands, PowerView, AdFind, and BloodHound/SharpHound to enumerate domains, identify targets, and progress toward domain admin privileges that can enable ransomware deployment or data exfiltration. It highlights detection challenges due to dual-use administrative tools and positions AhnLab EDR as a solution for monitoring, detecting, and responding to these behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.