Woodgnat AD Recon via net.exe or WMIC from Scripting Parent Process
Detects post-compromise Active Directory reconnaissance activities using net.exe or wmic.exe to enumerate domain users, groups, computers, and sessions. The rule identifies anomalous behavior by monitoring for at least 3 distinct reconnaissance categories triggered by common scripting interpreters (PowerShell, cmd, pythonw, or node.exe) within a 5-minute window.
Microsoft Sentinel (KQL)

