Windows: Uncommon Network Connections to AD Web Services (ADWS) from Non-Standard Processes
Alerts on unexpected process-to-ADWS (TCP/9389) connections on Windows to highlight potential directory discovery.
FreeUnreviewedSigmamediumv1
windows-uncommon-network-connections-to-ad-web-services-adws-from-non-standard-p-b3ad3c0f
title: "Windows: Uncommon Network Connections to AD Web Services (ADWS) from Non-Standard Processes"
id: 35cf1576-467b-43b2-aa74-69cd88743748
status: test
description: This rule flags outbound connections to Active Directory Web Services (ADWS) over TCP port 9389 when initiated by processes other than those typically used for ADWS management. Attackers may use ADWS to query or collect directory information, so unexpected binaries making these connections can indicate discovery activity. It relies on Windows network connection telemetry that includes the initiating process image path and the destination port.
references:
- https://medium.com/falconforce/soaphound-tool-to-collect-active-directory-data-via-adws-165aca78288c
- https://github.com/FalconForceTeam/FalconFriday/blob/a9219dfcfd89836f34660223f47d766982bdce46/Discovery/ADWS_Connection_from_Unexpected_Binary-Win.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/network_connection/net_connection_win_adws_unusual_connection.yml
author: "@kostastsale, Huntrule Team"
date: 2024-01-26
tags:
- attack.discovery
- attack.t1087
logsource:
category: network_connection
product: windows
detection:
selection:
Initiated: true
DestinationPort: 9389
filter_main_dsac:
Image: C:\Windows\system32\dsac.exe
filter_main_ms_monitoring_agent:
Image: C:\Program Files\Microsoft Monitoring Agent\
filter_main_powershell:
Image|startswith:
- C:\Program Files\PowerShell\7\pwsh.exe
- C:\Program Files\PowerShell\7-preview\pwsh.ex
- C:\Windows\System32\WindowsPowerShell\
- C:\Windows\SysWOW64\WindowsPowerShell\
condition: selection and not 1 of filter_main_*
falsepositives:
- ADWS is used by a number of legitimate applications that need to interact with Active Directory. These applications should be added to the allow-listing to avoid false positives.
level: medium
license: DRL-1.1
related:
- id: b3ad3c0f-c949-47a1-a30e-b0491ccae876
type: derived
What it detects
This rule flags outbound connections to Active Directory Web Services (ADWS) over TCP port 9389 when initiated by processes other than those typically used for ADWS management. Attackers may use ADWS to query or collect directory information, so unexpected binaries making these connections can indicate discovery activity. It relies on Windows network connection telemetry that includes the initiating process image path and the destination port.
Known false positives
- ADWS is used by a number of legitimate applications that need to interact with Active Directory. These applications should be added to the allow-listing to avoid false positives.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.