โ† Back to hub

Post-Compromise LDAP Reconnaissance in Active Directory (FDR)

Detects aggressive Active Directory enumeration via LDAP/LDAPS connections from non-standard processes, a common technique after initial compromise in domain-joined environments per the LOTL model of hands-on-keyboard adversaries

๐Ÿ”’

Premium Content

This query requires an active subscription to access the code.

Get Access