A Hitch-hacker's Guide to DACL-Based Detections (Part 1A)
ID: 0ba8eb25-2c27-507b-9e4b-5341e2f978dc
STIX ID: report--0ba8eb25-2c27-507b-9e4b-5341e2f978dc
Feed Name: TrustedSec blog
This blog post details Active Directory attack techniques and corresponding detection strategies: it walks through attacks that modify AD attributes (SPNs, delegation settings, shadow credentials, logon scripts, RDP initial programs, and GPOs), demonstrates how the modifications are performed (with tools like PowerMad, Whisker, GPOwned), and provides Splunk/SPL queries and Windows Event ID correlation patterns (5136, 4662, 4624, 5145, 4742, etc.) to detect such abuses across a domain environment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
