Synopsis
Description
Uncommon net localgroup command execution.
Attacker's Goals
Attackers may attempt to use the command to find local groups permissions settings or modify local memberships.
Investigative actions
- Check if the queried group is a sensitive one (e.g. administrators).
- Check whether the initiating process has executed additional discovery commands.
Variations
Uncommon net localgroup administrators command execution by a web server process or CGO
Synopsis
Description
Uncommon net localgroup command execution. When executed from a web server, it might be executed from an installed Webshell.
Attacker's Goals
Attackers may attempt to use the command to find local groups permissions settings or modify local memberships.
Investigative actions
- Check if the queried group is a sensitive one (e.g. administrators).
- Check whether the initiating process has executed additional discovery commands.
Uncommon unsigned net localgroup administrators command execution
Synopsis
Description
Uncommon net localgroup command execution.
Attacker's Goals
Attackers may attempt to use the command to find local groups permissions settings or modify local memberships.
Investigative actions
- Check if the queried group is a sensitive one (e.g. administrators).
- Check whether the initiating process has executed additional discovery commands.
Uncommon net localgroup administrators command execution
Synopsis
Description
Uncommon net localgroup command execution.
Attacker's Goals
Attackers may attempt to use the command to find local groups permissions settings or modify local memberships.
Investigative actions
- Check if the queried group is a sensitive one (e.g. administrators).
- Check whether the initiating process has executed additional discovery commands.
Uncommon net localgroup execution
Synopsis
Description
Uncommon net localgroup command execution.
Attacker's Goals
Attackers may attempt to use the command to find local groups permissions settings or modify local memberships.
Investigative actions
- Check if the queried group is a sensitive one (e.g. administrators).
- Check whether the initiating process has executed additional discovery commands.
Uncommon remote net localgroup execution
Synopsis
Description
Uncommon net localgroup command execution.
Attacker's Goals
Attackers may attempt to use the command to find local groups permissions settings or modify local memberships.
Investigative actions
- Check if the queried group is a sensitive one (e.g. administrators).
- Check whether the initiating process has executed additional discovery commands.
Uncommon administrator net localgroup execution by scripting engine or command prompt
Synopsis
Description
Uncommon net localgroup command execution.
Attacker's Goals
Attackers may attempt to use the command to find local groups permissions settings or modify local memberships.
Investigative actions
- Check if the queried group is a sensitive one (e.g. administrators).
- Check whether the initiating process has executed additional discovery commands.