Detecttechnique
D3-ANAAAdministrative Network Activity Analysis
Administrative Network Activity Analysis
Definition
Detection of unauthorized use of administrative network protocols by analyzing network activity against a baseline.
Defends against8
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Accessibility Featurest1546.008 | 100% | live |
| SubTechnique | Credential Stuffingt1110.004 | 100% | live |
| Technique | Windows Management Instrumentationt1047 | 100% | live |
| SubTechnique | Windows Management Instrumentation Event Subscriptiont1546.003 | 100% | live |
| SubTechnique | Additional Cloud Credentialst1098.001 | 100% | live |
| SubTechnique | Password Sprayingt1110.003 | 100% | live |
| Technique | Rogue Domain Controllert1207 | 100% | live |
| SubTechnique | DCSynct1003.006 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.