mdecrevoisier high experimental sigma
AdminSDHolder permissions changed for persistence
Detects scenarios where an attacker changes permissions on the AdminSDHolder container to establish persistence.
Detection Logic
{
"selection": {
"EventID": 5136,
"OperationType": "%%14674",
"AttributeLDAPDisplayName": "nTSecurityDescriptor",
"ObjectDN
| startswith": "CN=AdminSDHolder,CN=System,*"
},
"condition": "selection"
} False Positives
- ⚠ Unknown
Field Validations
Loading…
Comments (0)
Loading comments...