Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1069.002

T1069.002Domain Groups

T1069.002 — Domain Groups is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 23 detection use cases covering it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
23Use cases
0Articles
0Sub-techniques
1Tactic

Use cases covering this technique (23)

Detect AzureHound Command-Line Arguments ESCU actions · alerting P Detect AzureHound File Modifications ESCU actions · alerting P Detect SharpHound Command-Line Arguments ESCU actions · alerting P Detect SharpHound File Modifications ESCU actions · alerting P Detect SharpHound Usage ESCU actions · alerting P Domain Group Discovery with Adsisearcher ESCU actions · alerting P Domain Group Discovery With Dsquery ESCU actions · hunting P Domain Group Discovery With Wmic ESCU actions · hunting P Elevated Group Discovery with PowerView ESCU actions · hunting P Elevated Group Discovery With Wmic ESCU actions · alerting P GetAdGroup with PowerShell ESCU actions · hunting P GetAdGroup with PowerShell Script Block ESCU actions · hunting P GetDomainGroup with PowerShell ESCU actions · alerting P GetDomainGroup with PowerShell Script Block ESCU actions · alerting P GetWmiObject Ds Group with PowerShell ESCU actions · hunting P GetWmiObject Ds Group with PowerShell Script Block ESCU actions · alerting P Network Traffic to Active Directory Web Services Protocol ESCU actions · hunting P Windows Group Discovery Via Net ESCU actions · hunting P Windows Ldifde Directory Object Behavior ESCU actions · alerting P Windows Sensitive Group Discovery With Net ESCU actions · hunting P Windows SOAPHound Binary Execution ESCU actions · alerting P Domain Group Discovery With Net ESCU actions · hunting P Elevated Group Discovery With Net ESCU actions · alerting P