logo

A Hitch-hacker's Guide to DACL-Based Detections (Part 1A)

ID: 0ba8eb25-2c27-507b-9e4b-5341e2f978dc

STIX ID: report--0ba8eb25-2c27-507b-9e4b-5341e2f978dc

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-03-24

Date Updated: 2026-05-01

...
...

This blog post details Active Directory attack techniques and corresponding detection strategies: it walks through attacks that modify AD attributes (SPNs, delegation settings, shadow credentials, logon scripts, RDP initial programs, and GPOs), demonstrates how the modifications are performed (with tools like PowerMad, Whisker, GPOwned), and provides Splunk/SPL queries and Windows Event ID correlation patterns (5136, 4662, 4624, 5145, 4742, etc.) to detect such abuses across a domain environment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.