Forum Discussion
Tali Ash
Microsoft
Feb 26, 2019New preview detection: Security principal reconnaissance (LDAP)
We are proud to introduce a new alert in preview mode that addresses Security principal reconnaissance (LDAP). This type of reconnaissance is typically used by attackers to gain critical information...
echavez370
Mar 23, 2021Copper Contributor
Are there any plans to update this alert to include what actor performed the query? It's very unhelpful to say "an actor on server sent a suspicious LDAP query" without specifying the actor. Tali Ash
EliOfek
Microsoft
Mar 24, 2021We don't have the actor as this is happening using the machine account.
If you have MDE on the machine you might have more data to cross with to find the actor.
If you have MDE on the machine you might have more data to cross with to find the actor.
- mboisvertMay 24, 2023Copper Contributor
EliOfekSource? That would be useful if it was in the documentation of Msft and we don't need to ask on techcommunity. Do you have any suggestions to correlate this alert with factual events on the machine? That would be useful too. Thanks.
- EliOfekMay 24, 2023
Microsoft
mboisvert If you look closely at the alert details, even export it excel you will be able to see that the entity involved in this case is the machine account.
Note that this could happen to other alerts as well if the attacker used the machine account.
If you have specific recommendation of what specific statement you are missing from the docs and where, I am adding Deleted to help with that.- mboisvertMay 24, 2023Copper Contributor
EliOfek Thanks for the quick reply. Yes I remember we could do this in the OLD portal. But I think it is not possible in M365 Defender now. In any way, would it be possible to have it IN the alert and no need to do an extra steps to avoid that confusion? In m365 defender, this is what the alert gives us: Timestamp, Base Object, Search Scope, Search Filter, Enumeration Type, Sensitive Type, Queried Groups. Basically, only what was queried, but no context (process, command line...). There is no correlation at all, so it is difficult to investigate accordingly. I found some documentation online, but either the Schema or the Action type in the queries given as examples doesn't exist. Do you have any documentation to help costumers investigating such alerts?