Discovery/Recon Detection on Windows Hosts

Virtual machines to power on:

DC

WIN11V


Once a threat actor finds themselves in an environment, they will most likely need to undertake some kind of reconnaissance activities. The MITRE ATT&CK Discovery section contains 32 techniques, with various sub techniques: https://attack.mitre.org/tactics/TA0007/

Like many other sections in this course, this is one where you can deep dive into - for our purposes however, rather than covering how to detect each and every single discovery technique, let's spend some time on how to approach these types of detections more broadly.

Looking at one of the fantastic DFIR Report write-ups ( https://thedfirreport.com/2023/10/30/netsupport-intrusion-results-in-domain-compromise/ ), we can get a quick since of what discovery looks like when executed by a threat actor:

Let's go ahead and issue some of these commands on our Win11V host, in a command prompt:

Let's start with a broad query, looking at Sysmon events and displaying what command lines were issued by a parent command line:

_sourcename = "Microsoft-Windows-Sysmon/Operational"
| where EventID = 1
| %"EventData.Image" as Image
| %"EventData.ParentImage" as ParentImage
| %"EventData.CommandLine" as CommandLine
| %"EventData.ParentCommandLine" as ParentCommandLine
| values(CommandLine) as CommandLines by ParentCommandLine

And looking at our results:

Without specifically looking for our recon commands, we see them generally stick out when looking at our telemetry. Let's filter this query down further and look for specific recon commands:

_sourcename = "Microsoft-Windows-Sysmon/Operational"
| where EventID = 1
| %"EventData.Image" as Image
| %"EventData.ParentImage" as ParentImage
| %"EventData.CommandLine" as CommandLine
| %"EventData.ParentCommandLine" as ParentCommandLine
| where CommandLine matches /(net group|net user|cmdkey|systeminfo|whoami)/
| values(CommandLine) as CommandLines,count(CommandLine) as ReconCommandCount by ParentCommandLine 

In this query, we are:

  • Looking at Sysmon Event ID 1 Process Creation events

  • Renaming the Image,ParentImage,CommandLine and ParentCommandLine fields

  • Running a regular expression that looks for recon commands, we can add more here as we discover additional potential recon commands

  • Displaying the values of the command line and counting how many times a recon command was found, sorted by the ParentCommandLine

And looking at our results:

If you recall, we ran some recon commands like whoami through some of our earlier executions, so let's broaden the time frame of the query and look at the results - since we are looking at a broader time period ( try something like 7 days, this will depend on when you performed the prior execution, also keep in mind the free version of Sumo Logic will have a retention of 7 days ):

_sourcename = "Microsoft-Windows-Sysmon/Operational"
| where EventID = 1
| %"EventData.Image" as Image
| %"EventData.ParentImage" as ParentImage
| %"EventData.CommandLine" as CommandLine
| %"EventData.ParentCommandLine" as ParentCommandLine
| timeslice 1d
| where CommandLine matches /(net group|net user|cmdkey|systeminfo|whoami)/
| values(CommandLine) as CommandLines,count(CommandLine) as ReconCommandCount by ParentCommandLine,_timeslice

And our results:

We see the recon commands that we just ran, as well as our previous WMIExec execution - and we also see some other recon commands that we ran, either in the course of building the lab, troubleshooting or maybe our PSExec executions.

The discovery / recon category is one where it is extremely difficult to gain an understanding of whether a particular execution is actually malicious or not. Counting the number of recon commands per user, per process or per time period is a great approach, but it lacks context - that is, do we know whether a particular recon command was issued for the first time?

This temporal element is very important, if an administrator runs whoami, ipconfig etc every day or even every week in the context of their job duties, this is probably expected behavior, however, if that same administrator runs a recon command for the first time in a given time period, this might be a little bit more suspicious.

Let's narrow our query time frame from the above 7 days and add a time comparison operator:

_sourcename = "Microsoft-Windows-Sysmon/Operational"
| where EventID = 1
| %"EventData.Image" as Image
| %"EventData.ParentImage" as ParentImage
| %"EventData.CommandLine" as CommandLine
| %"EventData.ParentCommandLine" as ParentCommandLine
| where CommandLine matches /(net group|net user|cmdkey|systeminfo|whoami)/
| values(CommandLine) as CommandLines,count(CommandLine) as ReconCommandCount by ParentCommandLine 
| compare with timeshift 1d

Now we can tweak our query, adding some logic for when there were no recon commands a day ago compared to today and when the recon command count is over three:

_sourcename = "Microsoft-Windows-Sysmon/Operational"
| where EventID = 1
| %"EventData.Image" as Image
| %"EventData.ParentImage" as ParentImage
| %"EventData.CommandLine" as CommandLine
| %"EventData.ParentCommandLine" as ParentCommandLine
| where CommandLine matches /(net group|net user|cmdkey|systeminfo|whoami)/
| values(CommandLine) as CommandLines,count(CommandLine) as ReconCommandCount by ParentCommandLine 
| compare with timeshift 1d 
| if(isNull(ReconCommandCount_1d),"no","yes") as ReconDayAgo
| where ReconCommandCount > 3 AND ReconDayAgo = "no"
| fields ParentCommandLine,CommandLines,ReconCommandCount,ReconDayAgo

The goal in this section isn't to provide queries for every possible recon command available, as that would be infeasible, but rather to highlight different strategies and techniques that can be used to detect this type of activity.


References:

  • https://thedfirreport.com/


    Section mind map

Constructing Defense

Buy nowLearn more
  • 🚨Important Changes Coming to Constructing Defense - Please Read ⚠️3

Welcome to Constructing Defense!

  • Welcome & Introduction
  • Changelog

Lab Overview

  • Lab Overview4
  • General Lab Build Approach2

Lab Construction

  • ISO Downloads - Windows Server 20192
  • ISO Downloads - Windows 11
  • ISO Downloads - Ubuntu2
  • ISO Downloads - PCAP3

Lab Construction - AWS Version

  • Terraform Setup9
  • Domain Controller
  • Windows 11 A & V
  • Certer
  • Linux A & Linux V2

[Splunk] - Lab Construction & Provisioning - Ludus Version

  • [Splunk] - Ludus Overview5
  • [Splunk] - Ludus Deploy4
  • [Splunk] - Ludus Post Deploy Setup

Lab Construction & Provisioning - Ludus Version

  • Ludus Overview
  • Ludus Setup10
  • Ludus Post Deploy Setup4

Lab Provisioning

  • Domain Controller6
  • Windows 11 A & V7
  • Certer
  • Linux A & Linux V4
  • PCAP15
  • PCAP - New Malcolm Version10
  • Cloud Accounts - Azure1
  • Cloud Accounts - Amazon Web Services (AWS)1
  • Kubernetes Setup
  • Sysmon Setup7

Telemetry Setup & Miscellaneous Lab Configuration

  • Section Intro
  • Windows Auditing and GPO Setup
  • Disabling Defender
  • Certificate Enrollment
  • Linux Auditd + Laurel19
  • Sumo Logic SIEM Account
  • [Sumo Logic] - Windows Event Collection3
  • [Sumo Logic] - Linux Event Collection3
  • [Legacy] - Kubernetes Monitoring
  • [Sumo Logic] - Kubernetes Monitoring5
  • [Sumo Logic] - Cloud Collection - AWS5
  • [Sumo Logic] - Cloud Collection - Azure5
  • [Splunk] - Splunk Setup
  • [Splunk] - Forwarder Setup (Windows)5
  • [Splunk] - Forwarder Setup (Linux)3
  • [Splunk] - Kubernetes Monitoring9
  • [Splunk] - Cloud Collection - AWS5
  • [Splunk] - Cloud Collection - Azure/Entra

Lab Executions

  • Section Intro
  • Getting to Know Ourselves3
  • Our First Shell1
  • First Shell - Detection 1
  • First Shell - Detection 2
  • Our Second Shell - Exploring the Network Layer5
  • Second Shell - Bonus Round
  • Credential Access on Windows Hosts - LSASS
  • Credential Access on Windows Hosts - File Shares1
  • Credential Access on Windows Hosts - Kerberoasting
  • Credential Access on Windows Hosts - DCSync
  • Lateral Movement in Windows Environments - WMIExec5
  • Lateral Movement in Windows Environments - PSExec
  • Discovery/Recon Detection on Windows Hosts
  • Profiling Rundll32 Executions on Windows Hosts
  • LOLBAS / LOLBINs
  • Active Directory Certificate Services3
  • Authentication Anomalies on Windows Hosts - The Classic Brute Force
  • Authentication Anomalies on Windows Hosts - The Kerberos Approach
  • Credential Access on Linux Hosts - The Shadow File
  • Credential Access on Linux Hosts - Through a C2 Framework
  • Lateral Movement on Linux Hosts - Interactive Bash Prompts
  • Web Shell Detections on Linux Hosts
  • Kubernetes Threat Detection - Dipping our Toes
  • Kubernetes Threat Detection - The Host Layer
  • Kubernetes Threat Detection - The Host Layer - Enumeration
  • Kubernetes Threat Detection - Tunneling & Exposed Services
  • Kubernetes Goat 🐐
  • Kubernetes Threat Detection - Poisoned Pod
  • Azure - Password Sprays
  • Azure - MFA Madness
  • Azure - Wrangling Applications
  • [Legacy] - Azure - Bad to the Bone3
  • [Updated] - Azure - Bad to the Bone
  • Azure - AzureHound2
  • Azure/Entra Session Hijacking via Browser Cookie Theft 🍪
  • Azure Session Hijack via HAR File
  • AWS - Account Set Up and CLI Access2
  • AWS - CloudTrail - IAM User Creation
  • AWS - CloudTrail - IAM User Enumeration
  • AWS - CloudTrail - Pacu - IAM Brute Force
  • AWS - CloudTrail - Pacu - S3 Bucket Exfil
  • Adding a bit of Purple
  • Endpoint Analysis with Hayabusa and Langchain
  • Kerberos Attacks & Defenses - Pass the Ticket
  • Kerberos Attacks & Defenses - Golden Ticket
  • Web Sockets & .NET Assemblies
  • DPAPI at the Host and Network Layer
  • Purple Teaming Memory Forensics with MemProcFS

Lab Executions - Splunk

  • [Splunk] - Getting to Know Ourselves
  • [Splunk] - Our First Shell3
  • [Splunk] First Shell - Detection 12
  • [Splunk] - First Shell - Detection 2
  • [Splunk] - Our Second Shell - Exploring the Network Layer2
  • [Splunk] - Second Shell - Bonus Round
  • [Splunk] - Credential Access on Windows Hosts - LSASS
  • [Splunk] - Credential Access on Windows Hosts - File Shares
  • [Splunk] - Credential Access on Windows Hosts - Kerberoasting
  • [Splunk] - Credential Access on Windows Hosts - DCSync
  • [Splunk] - Lateral Movement in Windows Environments - WMIExec
  • [Splunk] - Lateral Movement in Windows Environments - PSExec
  • [Splunk] - Discovery/Recon Detection on Windows Hosts
  • [Splunk] - Profiling Rundll32 Executions on Windows Hosts
  • [Splunk] - LOLBAS / LOLBINs
  • [Splunk] - Active Directory Certificate Services
  • [Splunk] - Authentication Anomalies on Windows Hosts - The Classic Brute Force
  • [Splunk] - Authentication Anomalies on Windows Hosts - The Kerberos Approach
  • [Splunk] - Credential Access on Linux Hosts - The Shadow File
  • [Splunk] - Credential Access on Linux Hosts - Through a C2 Framework
  • [Splunk] - Lateral Movement on Linux Hosts - Interactive Bash Prompts
  • [Splunk] - Web Shell Detections on Linux Hosts
  • [Splunk] - Kubernetes Threat Detection - Dipping our Toes
  • [Splunk] - Kubernetes Threat Detection - The Host Layer
  • [Splunk] - Kubernetes Threat Detection - The Host Layer - Enumeration
  • [Splunk] - Kubernetes Threat Detection - Tunneling & Exposed Services
  • [Splunk] - Kubernetes Goat 🐐
  • [Splunk] - Kubernetes Threat Detection - Poisoned Pod
  • [Splunk] - Azure - Password Sprays
  • [Splunk] - Azure - MFA Madness
  • [Splunk] - Azure - Wrangling Applications
  • [Legacy] - Azure - Bad to the Bone
  • [Updated] - Azure - Bad to the Bone
  • [Splunk] - Azure - AzureHound
  • [Splunk] - Azure/Entra Session Hijacking via Browser Cookie Theft 🍪
  • [Splunk] - Azure Session Hijack via HAR File
  • [Splunk] - AWS - Account Set Up and CLI Access
  • [Splunk] - AWS - CloudTrail - IAM User Creation
  • [Splunk] - AWS - CloudTrail - IAM User Enumeration
  • [Splunk] - AWS - CloudTrail - Pacu - IAM Brute Force
  • [Splunk] - AWS - CloudTrail - Pacu - S3 Bucket Exfil
  • [Splunk] - Adding a bit of Purple
  • [Splunk] - Endpoint Analysis with Hayabusa and Langchain
  • [Splunk] - Kerberos Attacks & Defenses - Pass the Ticket
  • [Splunk] - Kerberos Attacks & Defenses - Golden Ticket
  • [Splunk] - Web Sockets & .NET Assemblies
  • [Splunk] - Purple Teaming Memory Forensics with MemProcFS

Saying Goodbye 👋

  • Outro4