Reconnaissance using Directory Services queries

Fahad Noaman 131 Reputation points
2020-09-08T07:31:46.573+00:00

We have been receiving floods of alert on "Reconnaissance using Directory Services queries" with newly created account.

machine across the domain is trying to queried the newly created account.
23242-image.png

when checking few of the source machine, we found below warning in event log, kindly help to find the fix.

Remote calls to the SAM database n it have been denied in the past 900 seconds throttling window.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,193 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

Accepted answer
  1. JamesTran-MSFT 36,371 Reputation points Microsoft Employee
    2020-09-08T23:16:03.567+00:00

    @Fahad Noaman
    Thank you for your post!

    Looking at your issue, you should be able to investigate this issue further by following the Reconnaissance using Directory Services queries documentation. Additionally, you can troubleshoot the issues using the ATA audit logs which can be found under the "Windows Event Logs" -> Applications and Services, Microsoft ATA.

    If you'd like to reach out to our Azure Advanced Thread Protection Team.

    Please let me know if you have any other questions.
    Thank you for your time and patience.

    Additional Links:
    Advanced Threat Analytics suspicious activity guidesuspicious-activity-guide
    User and Group membership reconnaissance (SAMR) (external ID 2021)


0 additional answers

Sort by: Most helpful