A Hitch-hacker's Guide to DACL-Based Detections (Part 3)
ID: 21415525-b2b0-539c-82b2-6085897fcb6d
STIX ID: report--21415525-b2b0-539c-82b2-6085897fcb6d
Feed Name: TrustedSec blog
This blog post (Part 3) catalogs Active Directory object and attribute abuse techniques (e.g., AdminSDHolder, msDS-SupportedEncryptionTypes, gPCMachineExtensionNames, gPCFileSysPath, ntSecurityDescriptor, cACertificate, primaryGroupID) and provides step‑by‑step attack examples, required auditing (SACL, Windows Event IDs), and detection queries (Splunk/SIEM) to identify such modifications. The focus is on post‑compromise behaviors and building detections for modifications that adversaries or red teams can use to maintain persistence or escalate privileges in a domain environment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
