Forum Discussion

SpeedRacer's avatar
SpeedRacer
Brass Contributor
May 04, 2017

Not seeing generated threat alerts in ATA

We're currently running ATA version 1.7.5757.57477 and as I was following along with the ATA Playbook, I performed three commands to see if I could generate the alerts in ATA:

 

  1. nslookup ls -d <domain> (this failed)
  2. net user /domain (this failed)
  3. net group /domain (success as I was able to see a list of all groups)

After running these three commands, I jumped into the ATA Console, but I never saw an alert associated with those commands.

 

Any ideas as to why I wouldn't see them? The system I'm running the commands from has never been flagged as being ok to run commands from so it hasn't been whitelisted per se.

 

Thx

      • JIDE-JIMOH's avatar
        JIDE-JIMOH
        Brass Contributor

        Can you try use one of the tools in sysinternals for your test. the ATA in my lab is working fine and detecting the lateral movement. If that does not working. i will help troubleshoot your ATA installation. 

Resources