Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[New Rule] [BBR] Active Directory Object Modification by SYSTEM #3835

Draft
wants to merge 3 commits into
base: main
Choose a base branch
from

Conversation

w0rk3r
Copy link
Contributor

@w0rk3r w0rk3r commented Jun 26, 2024

Issues

Part of #3005

Summary

Identifies modifications to active directory (AD) objects by the SYSTEM (S-1-5-18) user. This behavior can indicate that the attacker has achieved SYSTEM privileges in a domain controller, which attackers can obtain by exploiting vulnerabilities or abusing default group privileges (e.g., Server Operators), and is tampering with AD objects.

This should be very low volume based on the data I have right now and will be used to baseline DC activity to further explore at #3522

@w0rk3r
Copy link
Contributor Author

w0rk3r commented Jun 27, 2024

It seems that my assumption about noise is wrong, I'll redo the logic to limit noise

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backlog backport: auto bbr Building Block Rules Domain: Endpoint OS: Windows windows related rules Rule: New Proposal for new rule
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants