Hayabusa critical experimental sigma

DC Machine Account Network Logon from Non-DC Source IP

Detects a Domain Controller machine account authenticating from a source IP that is not a known Domain Controller. DC machine accounts should only authenticate locally or from other DCs during replication operations. Any logon event for a DC account from a workstation or non-DC host is anomalous and indicates one of the following: - Silver Ticket: attacker forged a Kerberos TGS for a DC machine account without requesting a TGT - Pass-the-Ticket: attacker is replaying a captured DC machine account TGS from a non-DC host - Overpass-the-Hash: attacker converted a stolen DC machine account hash into a Kerberos ticket and is authenticating from a non-DC host - Exploitation of certain vulnerabilities such as CVE-2026-54121 (Certighost): attacker obtained a DC certificate via ADCS CDC-chase abuse, authenticates via PKINIT as the DC from their own host, then performs DCSync

View Source

Detection Logic

{
  "security": {
    "Channel": "Security"
  },
  "selection": {
    "EventID": 4624,
    "TargetUserName
| endswith": "$",
    "TargetUserName
| expand": "%dc_machine_accounts%"
  },
  "filter_main_dc_source": {
    "IpAddress
| expand": "%dc_ip_addresses%"
  },
  "filter_main_loopback": [
    {
      "IpAddress": [
        "127.0.0.1",
        "::1",
        "::ffff:127.0.0.1",
        "-"
      ]
    },
    {
      "IpAddress
| startswith": "fe80:"
    }
  ],
  "condition": "security and (selection and not 1 of filter_main_*)"
}

False Positives

  • Unlikely if %dc_machine_accounts% and %dc_ip_addresses% are correctly populated.

Field Validations

Loading…

Comments (0)

Loading comments...