logo

SDFlags: The Log Field I Wasn't Looking at That Revealed How BloodHound Really Works

ID: cc77d4b2-87a4-505d-ac5f-c682494c3a58

STIX ID: report--cc77d4b2-87a4-505d-ac5f-c682494c3a58

Feed Name: Huntress Blog

Date Published: 2026-01-15

Date Updated: 2026-04-28

...
...

This report analyzes LDAP Event ID 1644 logs to expose how the rarely used SDFlags control—when paired with nTSecurityDescriptor requests—enables and betrays attack-path discovery by tools like BloodHound/SharpHound; it explains why SDFlags are necessary (SACL access constraints), how 0x4 (DACL) versus 0x5 (Owner+DACL) map to attacker objectives (e.g., group ownership paths), and provides high-confidence detection patterns (mass enumeration + nTSecurityDescriptor + SDFlags, especially 0x5 during group enumeration) that reliably differentiate attack-tool behavior from normal administrative activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.