Splunk SPL Queries for Detecting gMSA Attacks
ID: 18c562a6-8c36-5b6b-8885-3ed6a37322e0
STIX ID: report--18c562a6-8c36-5b6b-8885-3ed6a37322e0
Feed Name: TrustedSec blog
Threat Score
This blog post demonstrates simulated attacks against Active Directory group Managed Service Accounts (gMSA)—including reading `msDS-ManagedPassword`/`msDS-ManagedPasswordId` and harvesting the KDS Root Key—and provides Splunk SPL queries, Windows Event ID guidance (e.g., `4662`, `2946`, `4624`), and SACL auditing recommendations to detect and investigate these techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
