Potential AD User Enumeration From Non-Machine Account

 Original Source: [Sigma source]
Title: Potential AD User Enumeration From Non-Machine Account
Status: test
Description:Detects read access to a domain user from a non-machine account
References:
  -https://www.specterops.io/assets/resources/an_ace_up_the_sleeve.pdf
  -http://www.stuffithoughtiknew.com/2019/02/detecting-bloodhound.html
  -https://learn.microsoft.com/en-us/windows/win32/adschema/attributes-all
  -https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4662
Author: Maxime Thiebaut (@0xThiebaut)
Date: 2020-03-30
modified:2022-11-08
Tags:
  • -'attack.discovery'
  • -'attack.t1087.002'
Logsource:
  • product: windows
  • service: security
  • definition: Requirements: The "Read all properties" permission on the user object needs to be audited for the "Everyone" principal
Detection:
  selection:
    EventID: '4662'
    ObjectType|contains: 'bf967aba-0de6-11d0-a285-00aa003049e2'
    AccessMask|endswith:
      -'1?'
      -'3?'
      -'4?'
      -'7?'
      -'9?'
      -'B?'
      -'D?'
      -'F?'

  filter_main_machine_accounts:
    SubjectUserName|endswith: '$'
  filter_main_msql:
    SubjectUserName|startswith: 'MSOL_'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Administrators configuring new users.
Level: medium