Detection rules › Sigma

Password Change on Directory Service Restore Mode (DSRM) Account

Severity
high
Author
Thomas Patzke
Source
upstream

Detects potential attempts made to set the Directory Services Restore Mode administrator password. The Directory Service Restore Mode (DSRM) account is a local administrator account on Domain Controllers. Attackers may change the password in order to obtain persistence.

MITRE ATT&CK coverage

TacticTechniques
PersistenceT1098 Account Manipulation
Privilege EscalationT1098 Account Manipulation

Event coverage

ProviderEvent IDTitle
Security-Auditing4794An attempt was made to set the Directory Services Restore Mode administrator password.

Stages and Predicates

Stage 1: selection