Detection rules › Sigma

A New Trust Was Created To A Domain

Severity
medium
Author
Thomas Patzke
Source
upstream

Addition of domains is seldom and should be verified for legitimacy.

MITRE ATT&CK coverage

TacticTechniques
PersistenceT1098 Account Manipulation
Privilege EscalationT1098 Account Manipulation

Event coverage

ProviderEvent IDTitle
Security-Auditing4706A new trust was created to a domain.

Stages and Predicates

Stage 1: selection