logo

A Hitch-Hacker's Guide To DACL-Based Detections - The Addendum

ID: 0b11d7da-fb28-5f1d-8300-78003b32cb7a

STIX ID: report--0b11d7da-fb28-5f1d-8300-78003b32cb7a

Feed Name: TrustedSec blog

Date Published: 2025-03-25

Date Updated: 2026-05-01

...
...

This blog post documents several Active Directory attributes (e.g., operatingSystem, operatingSystemVersion, entryTTL, userPrincipalName, userCertificate), demonstrates how an attacker with sufficient domain privileges can modify them (using tools like PowerMad, Impacket, LDIFDE and dynamicObject creation), and provides Splunk/SPL detection queries and guidance for auditing and baselining to detect such changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.