5 Ways to Find Systems Running Domain Admin Processes
Tags
Common Information
Type | Value |
---|---|
UUID | 1b8df1d6-8fe9-4b0d-b5b1-20d87decb271 |
Fingerprint | 27896d124c43cce3 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | July 9, 2012, 7 a.m. |
Added to db | Jan. 18, 2023, 8:37 p.m. |
Last updated | Nov. 17, 2024, 12:58 p.m. |
Headline | 5 Ways to Find Systems Running Domain Admin Processes |
Title | 5 Ways to Find Systems Running Domain Admin Processes |
Detected Hints/Tags/Attributes | 47/1/15 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 1 | below.net |
|
Details | Domain | 2 | rangewalker.new |
|
Details | File | 2 | netsess.exe |
|
Details | File | 1 | dcs.txt |
|
Details | File | 2 | admins.txt |
|
Details | File | 2 | sessions.txt |
|
Details | File | 15 | ips.txt |
|
Details | File | 14 | names.txt |
|
Details | File | 63 | output.txt |
|
Details | File | 1 | nbsessions.txt |
|
Details | File | 3 | systems.txt |
|
Details | File | 1 | domain-admin.txt |
|
Details | IPv4 | 619 | 0.0.0.0 |
|
Details | IPv4 | 1 | 192.168.74.0 |
|
Details | IPv4 | 103 | 192.168.1.0 |