User and group membership reconnaissance (SAMR)

George OCAK 70 Reputation points
2023-12-13T16:40:09.4166667+00:00

Hello,

We have received "User and group membership reconnaissance (SAMR)" from defender.

I only see the enumeration events no commands, process etc. related.

I was wondering how to find root cause for these queries from the user machine.

There is nothing seems suspicious but still we try to find what user machines made these.

Thanks.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Defender | Microsoft Defender for Identity
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.