logo

Splunk SPL Queries for Detecting gMSA Attacks

ID: 18c562a6-8c36-5b6b-8885-3ed6a37322e0

STIX ID: report--18c562a6-8c36-5b6b-8885-3ed6a37322e0

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2025-03-24

Date Updated: 2026-05-01

...
...

This blog post demonstrates simulated attacks against Active Directory group Managed Service Accounts (gMSA)—including reading `msDS-ManagedPassword`/`msDS-ManagedPasswordId` and harvesting the KDS Root Key—and provides Splunk SPL queries, Windows Event ID guidance (e.g., `4662`, `2946`, `4624`), and SACL auditing recommendations to detect and investigate these techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.