Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[New Rule] Potential Active Directory Replication User Backdoor #3014

Merged
merged 12 commits into from
Jul 31, 2024

Conversation

w0rk3r
Copy link
Contributor

@w0rk3r w0rk3r commented Aug 14, 2023

Issues

Blocked by elastic/integrations#7381

Changes were merged and the PR was updated

Summary

Identifies the modification of the nTSecurityDescriptor attribute in a domain object with rights related to DCSync to a user/computer account. Attackers can use this backdoor to re-obtain access to hashes of any user/computer.

@w0rk3r w0rk3r added blocked Rule: New Proposal for new rule OS: Windows windows related rules labels Aug 14, 2023
@w0rk3r w0rk3r self-assigned this Aug 14, 2023
@botelastic
Copy link

botelastic bot commented Oct 20, 2023

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@botelastic botelastic bot added the stale 60 days of inactivity label Oct 20, 2023
@w0rk3r w0rk3r added the backlog label Oct 24, 2023
@botelastic botelastic bot removed the stale 60 days of inactivity label Oct 24, 2023
Copy link
Contributor

@terrancedejesus terrancedejesus left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Can you run toml-lint command on it please before merging.

@w0rk3r w0rk3r removed the blocked label Jul 4, 2024
@w0rk3r w0rk3r requested a review from Mikaayenson July 10, 2024 23:41
Copy link
Contributor

@Aegrah Aegrah left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

rules/windows/credential_access_dcsync_user_backdoor.toml Outdated Show resolved Hide resolved
rules/windows/credential_access_dcsync_user_backdoor.toml Outdated Show resolved Hide resolved
@w0rk3r w0rk3r merged commit 65cacb4 into main Jul 31, 2024
9 checks passed
@w0rk3r w0rk3r deleted the dcsync_backdoor branch July 31, 2024 15:02
protectionsmachine pushed a commit that referenced this pull request Jul 31, 2024
* [New Rule] Potential Active Directory Replication User Backdoor

* Update credential_access_dcsync_user_backdoor.toml

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

Co-authored-by: Ruben Groenewoud <78494512 [email protected]>

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

---------

Co-authored-by: Terrance DeJesus <99630311 [email protected]>
Co-authored-by: Ruben Groenewoud <78494512 [email protected]>

(cherry picked from commit 65cacb4)
protectionsmachine pushed a commit that referenced this pull request Jul 31, 2024
* [New Rule] Potential Active Directory Replication User Backdoor

* Update credential_access_dcsync_user_backdoor.toml

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

Co-authored-by: Ruben Groenewoud <78494512 [email protected]>

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

---------

Co-authored-by: Terrance DeJesus <99630311 [email protected]>
Co-authored-by: Ruben Groenewoud <78494512 [email protected]>

(cherry picked from commit 65cacb4)
protectionsmachine pushed a commit that referenced this pull request Jul 31, 2024
* [New Rule] Potential Active Directory Replication User Backdoor

* Update credential_access_dcsync_user_backdoor.toml

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

Co-authored-by: Ruben Groenewoud <78494512 [email protected]>

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

---------

Co-authored-by: Terrance DeJesus <99630311 [email protected]>
Co-authored-by: Ruben Groenewoud <78494512 [email protected]>

(cherry picked from commit 65cacb4)
protectionsmachine pushed a commit that referenced this pull request Jul 31, 2024
* [New Rule] Potential Active Directory Replication User Backdoor

* Update credential_access_dcsync_user_backdoor.toml

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

Co-authored-by: Ruben Groenewoud <78494512 [email protected]>

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

---------

Co-authored-by: Terrance DeJesus <99630311 [email protected]>
Co-authored-by: Ruben Groenewoud <78494512 [email protected]>

(cherry picked from commit 65cacb4)
protectionsmachine pushed a commit that referenced this pull request Jul 31, 2024
* [New Rule] Potential Active Directory Replication User Backdoor

* Update credential_access_dcsync_user_backdoor.toml

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

Co-authored-by: Ruben Groenewoud <78494512 [email protected]>

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

---------

Co-authored-by: Terrance DeJesus <99630311 [email protected]>
Co-authored-by: Ruben Groenewoud <78494512 [email protected]>

(cherry picked from commit 65cacb4)
protectionsmachine pushed a commit that referenced this pull request Jul 31, 2024
* [New Rule] Potential Active Directory Replication User Backdoor

* Update credential_access_dcsync_user_backdoor.toml

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

Co-authored-by: Ruben Groenewoud <78494512 [email protected]>

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

---------

Co-authored-by: Terrance DeJesus <99630311 [email protected]>
Co-authored-by: Ruben Groenewoud <78494512 [email protected]>

(cherry picked from commit 65cacb4)
zsohamwag pushed a commit to zsohamwag/zsoham-detection-rules that referenced this pull request Sep 13, 2024
…tic#3014)

* [New Rule] Potential Active Directory Replication User Backdoor

* Update credential_access_dcsync_user_backdoor.toml

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

Co-authored-by: Ruben Groenewoud <78494512 [email protected]>

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

* Update rules/windows/credential_access_dcsync_user_backdoor.toml

---------

Co-authored-by: Terrance DeJesus <99630311 [email protected]>
Co-authored-by: Ruben Groenewoud <78494512 [email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants