Detection rules › Sigma

Add or Remove Computer from DC

Severity
low
Author
frack113
Source
upstream

Detects the creation or removal of a computer. Can be used to detect attacks such as DCShadow via the creation of a new SPN.

MITRE ATT&CK coverage

TacticTechniques
Defense EvasionT1207 Rogue Domain Controller

Event coverage

ProviderEvent IDTitle
Security-Auditing4741A computer account was created.
Security-Auditing4743A computer account was deleted.

Stages and Predicates

Stage 1: selection

Neighbors

Often fire together

Rules that target events appearing in the same incident timelines. They pattern-match on adjacent steps of the same TTP, so an alert from one is often paired with alerts from these. Useful for triage context and for assembling chained-detection rules.