DC Machine Account Network Logon from Non-DC Source IP
Detects a Domain Controller machine account authenticating from a source IP that is not a known Domain Controller. DC machine accounts should only authenticate locally or from other DCs during replication operations. Any logon event for a DC account from a workstation or non-DC host is anomalous and indicates one of the following: - Silver Ticket: attacker forged a Kerberos TGS for a DC machine account without requesting a TGT - Pass-the-Ticket: attacker is replaying a captured DC machine account TGS from a non-DC host - Overpass-the-Hash: attacker converted a stolen DC machine account hash into a Kerberos ticket and is authenticating from a non-DC host - Exploitation of certain vulnerabilities such as CVE-2026-54121 (Certighost): attacker obtained a DC certificate via ADCS CDC-chase abuse, authenticates via PKINIT as the DC from their own host, then performs DCSync
Detection Logic
{
"security": {
"Channel": "Security"
},
"selection": {
"EventID": 4624,
"TargetUserName
| endswith": "$",
"TargetUserName
| expand": "%dc_machine_accounts%"
},
"filter_main_dc_source": {
"IpAddress
| expand": "%dc_ip_addresses%"
},
"filter_main_loopback": [
{
"IpAddress": [
"127.0.0.1",
"::1",
"::ffff:127.0.0.1",
"-"
]
},
{
"IpAddress
| startswith": "fe80:"
}
],
"condition": "security and (selection and not 1 of filter_main_*)"
} False Positives
- ⚠ Unlikely if %dc_machine_accounts% and %dc_ip_addresses% are correctly populated.
Field Validations
Loading…
Comments (0)
Loading comments...