Forum Discussion
Tali Ash
Microsoft
Feb 26, 2019New preview detection: Security principal reconnaissance (LDAP)
We are proud to introduce a new alert in preview mode that addresses Security principal reconnaissance (LDAP). This type of reconnaissance is typically used by attackers to gain critical information...
echavez370
Mar 23, 2021Copper Contributor
Are there any plans to update this alert to include what actor performed the query? It's very unhelpful to say "an actor on server sent a suspicious LDAP query" without specifying the actor. Tali Ash
- EliOfekMar 24, 2021
Microsoft
We don't have the actor as this is happening using the machine account.
If you have MDE on the machine you might have more data to cross with to find the actor.- mboisvertMay 24, 2023Copper Contributor
EliOfekSource? That would be useful if it was in the documentation of Msft and we don't need to ask on techcommunity. Do you have any suggestions to correlate this alert with factual events on the machine? That would be useful too. Thanks.
- EliOfekMay 24, 2023
Microsoft
mboisvert If you look closely at the alert details, even export it excel you will be able to see that the entity involved in this case is the machine account.
Note that this could happen to other alerts as well if the attacker used the machine account.
If you have specific recommendation of what specific statement you are missing from the docs and where, I am adding Deleted to help with that.