Forum Discussion
charles burch
Sep 17, 2018Copper Contributor
Queried Domain Admins
I was looking at a computer and on the logs, it shows a name of a person who is not a Domain Admin but has queried Domain Admins Queried next to his name. What does this mean?
Nicholas DiCola (SECURITY JEDI)
Sep 18, 2018Former Employee
Hi
It means a process running as the user ran a query against the domain admins group to enumerate the members of this group. Some apps do this. Is this something you would expect apps on your network to do? if so, its likely normal. if not its worth looking in to.
charles burch
Sep 18, 2018Copper Contributor
Nicholas,
Thank you for the replay. This is not normal on our network. What type of steps could you recommend to help look into this?