-
Notifications
You must be signed in to change notification settings - Fork 502
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[New Rule] Potential Active Directory Replication User Backdoor #3014
Conversation
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good. Can you run toml-lint command on it please before merging.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM!
Co-authored-by: Ruben Groenewoud <78494512 [email protected]>
* [New Rule] Potential Active Directory Replication User Backdoor * Update credential_access_dcsync_user_backdoor.toml * Update rules/windows/credential_access_dcsync_user_backdoor.toml Co-authored-by: Ruben Groenewoud <78494512 [email protected]> * Update rules/windows/credential_access_dcsync_user_backdoor.toml * Update rules/windows/credential_access_dcsync_user_backdoor.toml --------- Co-authored-by: Terrance DeJesus <99630311 [email protected]> Co-authored-by: Ruben Groenewoud <78494512 [email protected]> (cherry picked from commit 65cacb4)
* [New Rule] Potential Active Directory Replication User Backdoor * Update credential_access_dcsync_user_backdoor.toml * Update rules/windows/credential_access_dcsync_user_backdoor.toml Co-authored-by: Ruben Groenewoud <78494512 [email protected]> * Update rules/windows/credential_access_dcsync_user_backdoor.toml * Update rules/windows/credential_access_dcsync_user_backdoor.toml --------- Co-authored-by: Terrance DeJesus <99630311 [email protected]> Co-authored-by: Ruben Groenewoud <78494512 [email protected]> (cherry picked from commit 65cacb4)
* [New Rule] Potential Active Directory Replication User Backdoor * Update credential_access_dcsync_user_backdoor.toml * Update rules/windows/credential_access_dcsync_user_backdoor.toml Co-authored-by: Ruben Groenewoud <78494512 [email protected]> * Update rules/windows/credential_access_dcsync_user_backdoor.toml * Update rules/windows/credential_access_dcsync_user_backdoor.toml --------- Co-authored-by: Terrance DeJesus <99630311 [email protected]> Co-authored-by: Ruben Groenewoud <78494512 [email protected]> (cherry picked from commit 65cacb4)
* [New Rule] Potential Active Directory Replication User Backdoor * Update credential_access_dcsync_user_backdoor.toml * Update rules/windows/credential_access_dcsync_user_backdoor.toml Co-authored-by: Ruben Groenewoud <78494512 [email protected]> * Update rules/windows/credential_access_dcsync_user_backdoor.toml * Update rules/windows/credential_access_dcsync_user_backdoor.toml --------- Co-authored-by: Terrance DeJesus <99630311 [email protected]> Co-authored-by: Ruben Groenewoud <78494512 [email protected]> (cherry picked from commit 65cacb4)
* [New Rule] Potential Active Directory Replication User Backdoor * Update credential_access_dcsync_user_backdoor.toml * Update rules/windows/credential_access_dcsync_user_backdoor.toml Co-authored-by: Ruben Groenewoud <78494512 [email protected]> * Update rules/windows/credential_access_dcsync_user_backdoor.toml * Update rules/windows/credential_access_dcsync_user_backdoor.toml --------- Co-authored-by: Terrance DeJesus <99630311 [email protected]> Co-authored-by: Ruben Groenewoud <78494512 [email protected]> (cherry picked from commit 65cacb4)
* [New Rule] Potential Active Directory Replication User Backdoor * Update credential_access_dcsync_user_backdoor.toml * Update rules/windows/credential_access_dcsync_user_backdoor.toml Co-authored-by: Ruben Groenewoud <78494512 [email protected]> * Update rules/windows/credential_access_dcsync_user_backdoor.toml * Update rules/windows/credential_access_dcsync_user_backdoor.toml --------- Co-authored-by: Terrance DeJesus <99630311 [email protected]> Co-authored-by: Ruben Groenewoud <78494512 [email protected]> (cherry picked from commit 65cacb4)
…tic#3014) * [New Rule] Potential Active Directory Replication User Backdoor * Update credential_access_dcsync_user_backdoor.toml * Update rules/windows/credential_access_dcsync_user_backdoor.toml Co-authored-by: Ruben Groenewoud <78494512 [email protected]> * Update rules/windows/credential_access_dcsync_user_backdoor.toml * Update rules/windows/credential_access_dcsync_user_backdoor.toml --------- Co-authored-by: Terrance DeJesus <99630311 [email protected]> Co-authored-by: Ruben Groenewoud <78494512 [email protected]>
Issues
Blocked by elastic/integrations#7381Changes were merged and the PR was updated
Summary
Identifies the modification of the nTSecurityDescriptor attribute in a domain object with rights related to DCSync to a user/computer account. Attackers can use this backdoor to re-obtain access to hashes of any user/computer.