User and group membership reconnaissance (SAMR)

George OCAK 70 Reputation points
2023-12-13T16:40:09.4166667+00:00

Hello,

We have received "User and group membership reconnaissance (SAMR)" from defender.

I only see the enumeration events no commands, process etc. related.

I was wondering how to find root cause for these queries from the user machine.

There is nothing seems suspicious but still we try to find what user machines made these.

Thanks.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,155 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
175 questions
0 comments No comments
{count} votes