Massive Computers Reconnaissance



A massive number of authentication requests on multiple computers, using NTLM or Kerberos protocols and coming from the same source can be an indication of an attack, likely with BloodHound/SharpHound.

See Also

MITRE ATT&CK description

BloodHound tool

SharpHound tool

Indicator Details

Name: Massive Computers Reconnaissance

Codename: I-MassiveComputersRecon

Severity: Low

Type: Indicator of Attack

MITRE ATT&CK Information:
ID: T1069
Sub-technique of: T1069
Tactic: TA0007