The (!FALSE) Pattern: How SOAPHound Queries Disappear Before They Hit Your Logs
ID: f7f3490a-193b-5711-8963-2a546ce5e2a1
STIX ID: report--f7f3490a-193b-5711-8963-2a546ce5e2a1
Feed Name: Huntress Blog
The report details how Active Directory optimizes LDAP filters with non-existent attributes into the logged pattern (! (FALSE)), causing enumeration tool signatures (notably SOAPHound via ADWS on port 9389) to disappear from Event ID 1644 logs. It shows that SOAPHound’s consistent use of SDFlags:0x7 and distinctive attribute requests, often proxied from localhost, form a reliable detection pattern; it provides Sigma-style rules and contrasts with SharpHound to help defenders build robust, low-false-positive detections for AD reconnaissance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
