Tag
medium
advisory
Suspicious Use of PsLogList for Event Log Discovery and Evasion
1 rule 3 TTPsAdversaries are leveraging the legitimate Sysinternals utility PsLogList to perform account and system discovery by dumping Windows event logs, and for defense evasion by clearing or exporting these logs, increasing their ability to operate undetected and further compromise systems.
sysinternals
discovery
defense-evasion
account-discovery
log-clearing
windows
1r
3t
low
advisory
Windows Account Discovery of Administrator Accounts
2 rules 4 TTPsThe rule identifies instances of lower privilege accounts enumerating Administrator accounts or groups using built-in Windows tools like net.exe and wmic.exe, potentially indicating reconnaissance activity by an attacker after initial compromise.
Windows
discovery
account-discovery
2r
4t
low
advisory
Windows Account Discovery of Administrator Accounts
2 rules 4 TTPsAdversaries may execute the `net.exe` or `wmic.exe` commands to enumerate administrator accounts or groups, both locally and within the domain, to gather information for follow-on actions.
M365 Defender +2
discovery
account-discovery
windows
2r
4t