Detection rules › By eventMicrosoft-Windows-Security-Auditing event 47427 detection rules reference this event. View event page.Sigma (1)Possible DC Shadow Attack severity medium T1207 Elastic (1)Remote Computer Account DnsHostName Update T1068, T1078, T1078.002, T1098 Splunk (5)Detect Computer Changed with Anonymous Account T1210 Windows AD Cross Domain SID History Addition T1134.005 Windows AD Domain Controller Promotion T1207 Windows AD Privileged Account SID History Addition T1134.005 Windows AD Same Domain SID History Addition T1134.005