The Tale of the Lost, but not Forgotten, Undocumented NetSync: Part 2
ID: e0a36986-844d-5456-b3fc-5fba3b2480f8
STIX ID: report--e0a36986-844d-5456-b3fc-5fba3b2480f8
Feed Name: TrustedSec blog
This blog section analyzes the NetSync technique (abuse of Netlogon) from a defensive perspective, outlining host-based detection approaches that correlate Windows Event IDs 4624 and 5145, describing challenges normalizing Logon_ID fields in Splunk, and offering two Splunk query patterns (Olaf and Greg) for detection; it also documents test execution results and recommends controls including reducing machine account password age, enabling relevant auditing (including 4688 where feasible), and applying the CVE-2020-1472 patch and associated Microsoft guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
