logo

A Hitch-hacker's Guide to DACL-Based Detections (Part 2)

ID: d816a52a-fdb7-5365-9c9b-5ce3efaa27a5

STIX ID: report--d816a52a-fdb7-5365-9c9b-5ce3efaa27a5

Feed Name: TrustedSec blog

Threat Score
50/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This blog (Part 2 of a series) demonstrates how an attacker with a domain foothold can modify many Active Directory computer-object attributes (e.g., sAMAccountName, description, displayName, userAccountControl, dNSHostName, msDS-AdditionalDnsHostName, userParameters, altSecurityIdentities, mSMQSignCertificates/mSMQDigests) using PowerMad and other tools, and presents detection approaches using Windows Event IDs (such as 5136, 4662, 4624, 4742) and Splunk queries to detect and correlate those changes for monitoring and alerting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.