logo

A Hitch-hacker's Guide to DACL-Based Detections (Part 3)

ID: 21415525-b2b0-539c-82b2-6085897fcb6d

STIX ID: report--21415525-b2b0-539c-82b2-6085897fcb6d

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-03-24

Date Updated: 2026-05-01

...
...

This blog post (Part 3) catalogs Active Directory object and attribute abuse techniques (e.g., AdminSDHolder, msDS-SupportedEncryptionTypes, gPCMachineExtensionNames, gPCFileSysPath, ntSecurityDescriptor, cACertificate, primaryGroupID) and provides step‑by‑step attack examples, required auditing (SACL, Windows Event IDs), and detection queries (Splunk/SIEM) to identify such modifications. The focus is on post‑compromise behaviors and building detections for modifications that adversaries or red teams can use to maintain persistence or escalate privileges in a domain environment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.