Active Directory Monitoring & Detection başlıklı kaynağın profesyonel teknik özetidir. Aşağıda belgenin ana başlık ve içerik yapısı Türkçe açıklamalarla sunulmuştur.
ANOMAL GmbH | Ueberlandstrasse 1 | CH-8600 Dübendorf | hello@anomal.xyz | anomal.xyz Active Directory Monitoring Detection Compendium Zoran Savic November 2025 ANOMAL GmbH Ueberlandstrasse 1 8600 Dübendorf CH – Schwitzerland hello@anomal.xyz ANOMAL GmbH | Ueberlandstrasse 1 | CH-8600 Dübendorf | hello@anomal.xyz | anomal.xyz Content Executive Summary and Introduction ........................................................................... 4 Credential Access & Replication Abuse .........................................................................6 Potential Credential Access via DCSync ...
..................................................................... 7 EQL Rule Query .......................................................................................................... 7 First Time Seen Account Performing DCSync ........................................................... 8 Potential Active Directory Replication Account Backdoor ......................................... 9 Potential Kerberos Coercion via DNS-Based SPN Spoofing ....................................... 9 User Account Exposed to Kerberoasting ....................................................................
. 10 Kerberos Pre-Authentication Disabled for User ....................................................... 10 KRBTGT Delegation Backdoor .................................................................................. 11 Service Creation via Local Kerberos Authentication .................................................. 11 Privilege Escalation & Persistence in AD Objects ......................................................... 12 AdminSDHolder Backdoor ....................................................................................... 13 AdminSDHolder SDProp Exclusion Added ..............
..................................................... 13 Potential Shadow Credentials Added to AD Object ................................................... 14 Sensitive Privilege SeEnableDelegationPrivilege Assigned to a User ........................ 14 Potential Privileged Escalation via SamAccountName Spoofing ............................... 15 Suspicious Remote Registry Access via SeBackupPrivilege ..................................... 16 Group Policy Abuse for Privilege Addition................................................................. 17 Startup/Logon Script Added to Group Policy ...
Object ................................................. 17 Scheduled Task Execution at Scale via GPO ............................................................. 18 Modification of the msPKIAccountCredentials ......................................................... 18 Delegated Managed Service Account Modification by an Unusual User ..................... 19 dMSA Account Creation by an Unusual User ............................................................. 19 Discovery, Reconnaissance & DNS Abuse ................................................................... 20 Access to a Sensitive ...
LDAP Attribute ....................................................................... 21 Remote Computer Account DnsHostName Update .................................................. 22 Creation of a DNS-Named Record ............................................................................ 23 Potential WPAD Spoofing via DNS Record Creation .................................................. 23 Potential ADIDNS Poisoning via Wildcard Record Creation .......................................24 Lateral Movement & Relay Attacks ........................................................................
......... 25 Potential Computer Account Relay Activity .............................................................. 26 Potential Kerberos Relay Attack Against a Computer Account .................................. 27 ANOMAL GmbH | Ueberlandstrasse 1 | CH-8600 Dübendorf | hello@anomal.xyz | anomal.xyz Potential NTLM Relay Attack Against a Computer Account ....................................... 28 Potential Machine Account Relay Attack via SMB ..................................................... 29 Active Directory Forced Authentication from Linux Host – SMB Named Pipes ...........30 Account ...
& Group Management Anomalies ................................................................... 31 User Added to Privileged Group in Active Directory .................................................. 32 Active Directory Group Modification by SYSTEM ...................................................... 33 Account Configured with Never-Expiring Password ................................................. 34 WRITEDAC Access on Active Directory Object ......................................................... 35 Appendix ................................................................................
....................................... 36 Overview Table of All 34 Rules .................................................................................. 36 Windows Event ID Reference ................................................................................... 37 ANOMAL GmbH | Ueberlandstrasse 1 | CH-8600 Dübendorf | hello@anomal.xyz | anomal.xyz Executive Summary and Introduction Active Directory remains the core of identity and access management in almost every enterprise. It is the system that defines trust, authentication, and authorization across the entire infrastructure. Becau...
se of its central role, it is also the primary target for ransomware groups and advanced intrusion actors. Once attackers reach the domain layer, they gain the ability to control systems, disable defenses, and deploy malware at scale. Protecting Active Directory is therefore one of the most important objectives for any modern security operations center. This document defines a complete detection framework for on premise Active Directory monitoring using Elastic Security SIEM. It brings together every relevant detection rule that contributes to identifying compromise, persistence, or misuse wit...
hin the directory environment. The rules are organized by attack phase and mapped to the MITRE ATT&CK framework to ensure full coverage across discovery, credential access, privilege escalation, persistence, and lateral movement. The framework contains a curated set of detection rules distributed across these main chapters: ▪ Credential Access and Replication Abuse Detection of DCSync, Kerberoasting, and credential extraction through replication rights or Kerberos manipulation. ▪ Privilege Escalation and Persistence in AD Objects Monitoring of object and policy changes such as AdminSDHolder, G...
PO abuse, and shadow credentials. ▪ Discovery, Reconnaissance and DNS Abuse Early detection of LDAP queries, computer account manipulation, and DNS poisoning attempts. ▪ Lateral Movement and Relay Attacks Identification of NTLM and Kerberos relay chains and cross platform coercion. ▪ Account and Group Management Anomalies Detection of hidden privilege escalation through group membership and access control modifications. Each chapter explains the purpose of the detection area, provides the exact detection rule description, the MITRE mapping, and the full verified query as implemented in Elastic...
Belge toplam 15 paragraf içermektedir; tam metin /root/pdf klasöründeki kaynak dosyasında mevcuttur.