SDFlags: The Log Field I Wasn't Looking at That Revealed How BloodHound Really Works
ID: cc77d4b2-87a4-505d-ac5f-c682494c3a58
STIX ID: report--cc77d4b2-87a4-505d-ac5f-c682494c3a58
Feed Name: Huntress Blog
This report analyzes LDAP Event ID 1644 logs to expose how the rarely used SDFlags control—when paired with nTSecurityDescriptor requests—enables and betrays attack-path discovery by tools like BloodHound/SharpHound; it explains why SDFlags are necessary (SACL access constraints), how 0x4 (DACL) versus 0x5 (Owner+DACL) map to attacker objectives (e.g., group ownership paths), and provides high-confidence detection patterns (mass enumeration + nTSecurityDescriptor + SDFlags, especially 0x5 during group enumeration) that reliably differentiate attack-tool behavior from normal administrative activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
