04-Get-RoleGroup.md

November 19, 2023 · View on GitHub

Get-RoleGroup

Table of contents:

Overview

Why it matters?

A threat actor may run an enumeration command to retrieve a list of Microsoft Defender for Office (MDO) and Purview Compliance role groups as a method of Discovery to better understand your environment. In this scenario, it's important to be able to understand exactly what has happened to answer questions like:

  • Did the enumeration command run successfully?
  • If yes, did the attacker perform any further targeted enumeration?

This page will help you investigate the audit event for the Get-RoleGroup operation from a DFIR perspective in terms of:

  • Useful fields and the insight we can gain from them
  • Key fields of note and if applicable, how to decipher them

Pre-Requisites

  • Ensure you have access to the Audit Log following the guide in 01-Access
  • Search for the Get-RoleGroup operation, adjusting the date/time range and if applicable, including other relevant criteria to refine the search.

Important


The Get-RoleGroup operation isn't logged for ExchangeAdmin, in other words if an attacker was to enumerate Exchange Online Role Groups, they would be undetected. In fact, no Get- Operations are logged for the ExchangeAdmin RecordType.*

This is why the RecordType in the table below is SecurityComplianceCenterEOPCmdlet since enumeration attempts of MDO & Purview Compliance Role Groups are logged.

Operation                           RecordTypeRecordType NameScreenshot (Note: Some personal fields have been redacted)Description                                                        
Get-RoleGroup18SecurityComplianceCenterEOPCmdletGet-RoleGroup is an operation logged when an admin runs a command to retrieve a list of MDO & Purview Compliance Role Groups.

Note


The screenshot above shows the full audit record for this operation. Click on it to open a larger version in a new tab. Fields from this will be referenced throughout so follow along.


Useful fields

FieldInsight (Source)
CreationTimeFrom this, we know that the command was run on "16th August 2023 at 4:44 PM UTC"
UserIdFrom this, we know that that the user that ran the command was "attacker@domain(.)onmicrosoft.com"
ResultStatusFrom this, we know that the command executed successfully; value of "Success"

Key fields of note

The Parameters object shown below contains one piece of useful information relating to this operation:

FieldInsight
ParametersFrom this we can see that the command was run with a flag of "-Identity "Organization Management""

Important

This is important because the Organization Management role group is highly privileged. It's a group that Global Admins are added to by default.

Through this command an attacker could be able to better understand the config of this role group.


Note

Note the audit event used in this example is a more targeted form of enumeration, in the first instance an attacker would run the command without any parameters and the audit event for that can be found here. As you can see, there are no parameters supplied.

Fields to Decipher

None 👌🏽

Next Steps

Now that you've seen how to interpret the audit log record for when MDO & Purview Compliance Role Groups are enumerated, what can you do?

  • Monitor MDO & Purview Compliance Role Groups for any suspicious additions by looking for Audit events with Add-RoleGroupMember. This page shows the audit event within the ExchangeAdmin RecordType but similar steps could be followed for the SecurityComplianceCenterEOPCmdlet RecordType.

  • Monitor if an attacker is trying to retrieve members of these MDO & Purview Compliance Role Groups, we'll explore the audit event for this in the next part of this series.🚀