Analytics Story: Network Discovery

Description

Leverage searches that allow you to detect and investigate unusual activities that might relate to the network discovery, including looking for network configuration, settings such as IP, MAC address, firewall settings and many more.

Why it matters

Adversaries may use the information from System Network Configuration Discovery during automated discovery to shape follow-on behaviors, including determining certain access within the target network and what actions to do next.

Detections

Name ▲▼ Technique ▲▼ Type ▲▼
Windows Network Share Interaction Via Net Data from Network Shared Drive, Network Share Discovery Hunting
Linux System Network Discovery System Network Configuration Discovery Anomaly
Windows Detect Network Scanner Behavior Scanning IP Blocks, Vulnerability Scanning Anomaly
Internal Horizontal Port Scan Network Service Discovery TTP
Windows Netspy Network Scanner Execution Remote System Discovery, Active Scanning Anomaly
MacOS List Firewall Rules System Network Configuration Discovery Anomaly
Internal Vulnerability Scan Network Service Discovery, Vulnerability Scanning TTP
Internal Horizontal Port Scan NMAP Top 20 Network Service Discovery TTP
Internal Vertical Port Scan Network Service Discovery TTP

Data Sources

Name ▲▼ Platform ▲▼ Sourcetype ▲▼ Source ▲▼
CrowdStrike ProcessRollup2 Other crowdstrike:events:sensor crowdstrike
Sysmon EventID 1 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Windows Event Log Security 4688 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Sysmon for Linux EventID 1 Linux icon Linux sysmon:linux Syslog:Linux-Sysmon/Operational
Osquery Results Other osquery:results osquery
Sysmon EventID 3 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Cisco Secure Firewall Threat Defense Connection Event Other cisco:sfw:estreamer not_applicable
AWS CloudWatchLogs VPCflow AWS icon AWS aws:cloudwatchlogs:vpcflow aws_cloudwatchlogs_vpcflow

References


Source: GitHub | Version: 2