You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- No Windows event logs are generated (tested on Windows 2016 / 2019)
55
-
- Requires custom network level monitoring (unencrypted LDAP analysis or traffic volume for LDAPS)
54
+
- Nothing native in the Windows event logs are generated (tested on Windows 2016 / 2019)
55
+
- Microsoft Defender for Identity 2.228 (February 2024) adds [event ID 2437](https://learn.microsoft.com/en-us/defender-for-identity/reconnaissance-discovery-alerts#account-enumeration-reconnaissance-ldap-external-id-2437-preview) and is triggered if the number of failed requests (i.e. wrong guesses at usernames) crosses an unknown threshold
56
+
- Custom network level monitoring (unencrypted LDAP analysis or traffic volume for LDAPS) can also be used, though it's not reliable
0 commit comments