Unsigned LDAP Bind
Detects Lightweight Directory Access Protocol (LDAP) binds that are performed without signing or encryption. Attack tools such as NetExec, ldapdomaindump, and Impacket frequently use simple, unencrypted LDAP binds over port 389, which can result in the transmission of credentials in cleartext. This rule monitors Windows Event ID 2889 on Domain Controllers, which logs cleartext LDAP bind attempts.
Cortex XDR

