Detect Outbound LDAP Traffic(ASIM Network Session schema)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Malicious actors often abuse misconfigured LDAP servers or applications that use the LDAP servers in organizations. Outbound LDAP traffic should not be allowed outbound through your perimeter firewall.

Attribute Value
Type Hunting Query
Solution Network Session Essentials
ID 5dca6047-24ed-4eb7-b44e-ec7f1bf42621
Tactics InitialAccess, Execution
Techniques T1071, T1059
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Network Session Essentials