
Barsha Sketh
@Barshasketh0 followers4 downloads11 copies0 likes148 views
3 detections
Filters
Last updated
All Time
Detection languages
3
Categories
3
2
1
1
1
Platforms
3
Products / Services
3
1
MITRE Techniques
3
3
3
2
2
Detects the creation of new domain user accounts using the 'net user /add /domain' command. This activity can be indicative of an adversary establishing persistence or escalating privileges within a Windows domain environment.
Detects the addition of new domain accounts using the 'net group /add /domain' command. This activity can be indicative of an adversary establishing persistence or escalating privileges within a domain environment.
Detects PowerShell commands using encoded command-line arguments to execute 'net user', 'net group', or 'net share' commands. This technique is often used by adversaries to obfuscate their actions and evade detection.
