Files
splunk-security_content/stories/windows_domain_controller_attacks.yml
T
2022-09-30 17:33:44 -04:00

27 lines
1.3 KiB
YAML

name: Windows Domain Controller Attacks
id: f676c4c1-c769-4ecb-9611-5fd85b497c56
version: 1
date: '2022-08-29'
author: Dean Luxton, Mauricio Velazco
description: Monitor for activities and techniques associated with replication based attacks which target domain controllers and post-exploitation active directory persistence techniques.
narrative: This analytic story provides detections for some of the highest impact attacks which can be performed against an Active Directory network.
Featuring attacks which leverage flaws within replication (MS probably wont fix these any time soon), enabling backdoor accounts and other stealthy persistence techniques.
It is imperative to enable the necessary GPOs and SACLs required, otherwise the eventcodes will not trigger. Each detection includes a list of requirements for enabling logging.
references:
- https://adsecurity.org/?p=1929
- https://www.dcshadow.com
- https://gist.github.com/gentilkiwi/dcc132457408cf11ad2061340dcb53c2
- https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer
tags:
analytic_story: Windows Domain Controller Attacks
category:
- Adversary Tactics
- Account Compromise
- Lateral Movement
- Privilege Escalation
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection