A Hitch-hacker's Guide to DACL-Based Detections (Part…
ID: b9dcde2a-52d7-5042-adfa-9069b6a07d08
STIX ID: report--b9dcde2a-52d7-5042-adfa-9069b6a07d08
Feed Name: TrustedSec blog
This Part 1B technical blog details Active Directory attribute-based attack techniques (manipulating DACLs, ForceChangePassword, ownership changes, LAPS/gMSA abuses, and granting DCSync rights), demonstrates proof-of-concept abuse using common post-exploitation tools (PowerView, PowerSploit, Impacket, PowerMad), and supplies Splunk-oriented detection queries and SDDL analysis to help defenders detect and investigate such modifications and privileges escalation attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
