mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
27 lines
1.3 KiB
YAML
27 lines
1.3 KiB
YAML
name: Windows Domain Controller Attacks
|
|
id: f676c4c1-c769-4ecb-9611-5fd85b497c56
|
|
version: 1
|
|
date: '2022-08-29'
|
|
author: Dean Luxton, Mauricio Velazco
|
|
description: Monitor for activities and techniques associated with replication based attacks which target domain controllers and post-exploitation active directory persistence techniques.
|
|
narrative: This analytic story provides detections for some of the highest impact attacks which can be performed against an Active Directory network.
|
|
Featuring attacks which leverage flaws within replication (MS probably wont fix these any time soon), enabling backdoor accounts and other stealthy persistence techniques.
|
|
It is imperative to enable the necessary GPOs and SACLs required, otherwise the eventcodes will not trigger. Each detection includes a list of requirements for enabling logging.
|
|
references:
|
|
- https://adsecurity.org/?p=1929
|
|
- https://www.dcshadow.com
|
|
- https://gist.github.com/gentilkiwi/dcc132457408cf11ad2061340dcb53c2
|
|
- https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer
|
|
tags:
|
|
analytic_story: Windows Domain Controller Attacks
|
|
category:
|
|
- Adversary Tactics
|
|
- Account Compromise
|
|
- Lateral Movement
|
|
- Privilege Escalation
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Advanced Threat Detection
|