Rogue Domain Controller T1207
Tactic: Defense Impairment
Adversaries may register a rogue Domain Controller to enable manipulation of Active Directory data. DCShadow may be used to create a rogue Domain Controller (DC). DCShadow is a method of manipulating Active Directory (AD) data, including objects and schemas, by registering (or reusing an inactive registration) and simulating the behavior of a DC. Once registered, a rogue DC may be able to inject and replicate changes into AD infrastructure for any domain object, including credentials and keys.
Events covered
8 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Security-Auditing | Event ID 4624 | An account was successfully logged on. |
| Security-Auditing | Event ID 4662 | An operation was performed on an object. |
| Security-Auditing | Event ID 4741 | A computer account was created. |
| Security-Auditing | Event ID 4742 | A computer account was changed. |
| Security-Auditing | Event ID 4743 | A computer account was deleted. |
| Security-Auditing | Event ID 5136 | A directory service object was modified. |
| Security-Auditing | Event ID 5137 | A directory service object was created. |
| Security-Auditing | Event ID 5141 | A directory service object was deleted. |
Authoring guide
These 13 rules share fields, values, and exclusions.
Fields filtered most (19 distinct)
These fields appear most often in rule filters.
Top indicator values (35 distinct)
These values appear most often in rule predicates.
Exclusions (2 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 3 rules
- Account accessed to attributes related to DCshadow
- Add or Remove Computer from DC
- Possible DC Shadow Attack
Splunk 6 rules
- Windows AD DCShadow Privileges ACL Addition
- Windows AD Domain Controller Promotion
- Windows AD Replication Service Traffic
- Windows AD Rogue Domain Controller Network Activity
- Windows AD Short Lived Domain Controller SPN Attribute
- Windows AD Short Lived Server Object