Forum Discussion
SpeedRacer
May 04, 2017Brass Contributor
Not seeing generated threat alerts in ATA
We're currently running ATA version 1.7.5757.57477 and as I was following along with the ATA Playbook, I performed three commands to see if I could generate the alerts in ATA:
- nslookup ls -d <domain> (this failed)
- net user /domain (this failed)
- net group /domain (success as I was able to see a list of all groups)
After running these three commands, I jumped into the ATA Console, but I never saw an alert associated with those commands.
Any ideas as to why I wouldn't see them? The system I'm running the commands from has never been flagged as being ok to run commands from so it hasn't been whitelisted per se.
Thx
- JIDE-JIMOHBrass Contributor
Are you running the runbook on a Server or on a client OS ?
- SpeedRacerBrass Contributor
On a client OS - Windows 8
Thx
- JIDE-JIMOHBrass Contributor
Can you try use one of the tools in sysinternals for your test. the ATA in my lab is working fine and detecting the lateral movement. If that does not working. i will help troubleshoot your ATA installation.