diff --git a/nursery/get-domain-admins.yml b/nursery/get-domain-admins.yml new file mode 100644 index 000000000..06565a834 --- /dev/null +++ b/nursery/get-domain-admins.yml @@ -0,0 +1,19 @@ +rule: + meta: + name: get domain admins + namespace: collection/network + authors: + - kevross33/Kevin Ross + scopes: + static: function + dynamic: span of calls + att&ck: + - Discovery::Permission Groups Discovery [T1069] + examples: + - f5fca1b178af87bd48c7ea9e3f2c957b + features: + - and: + - string: /net/i + - string: /group/i + - string: /domain admins/i + - string: //domain/i