The 60ms Window: How Event 5156 Solves the ADWS Attribution Problem
ID: 75f3b2a8-83d9-521e-9c12-4dcf68154230
STIX ID: report--75f3b2a8-83d9-521e-9c12-4dcf68154230
Feed Name: Huntress Blog
This research demonstrates a practical detection technique to attribute ADWS-based Active Directory enumeration back to source IPs by correlating Windows Event 5156 (network connection), Event 1138 (ADWS session), and Event 1644 (LDAP query). The author validates a consistent ~60–80 ms timing window for correlation, provides a PowerShell script to automate attribution, and explains how SIEM log retention and pattern-based filtering reduce RSAT false positives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
