2

Recently I noticed that every few days, at (almost) the same time, one host is querying the Domain Controller for group members using SAMR calls. I am trying to understand why its happening continuously around the same time? is there a legitimate service that are automated to do so?

And how can I investigate that at the host level?

Onyx
  • 21
  • 1
  • I am searching on this too and this was the only possible legitimate activity i found so far. https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-samr/9699d8ca-e1a4-433c-a8c3-d7bebeb01476 – Pro Gram Aug 10 '21 at 17:46

0 Answers0