mdecrevoisier high experimental sigma

AdminSDHolder permissions changed for persistence

Detects scenarios where an attacker changes permissions on the AdminSDHolder container to establish persistence.

View Source

Detection Logic

{
  "selection": {
    "EventID": 5136,
    "OperationType": "%%14674",
    "AttributeLDAPDisplayName": "nTSecurityDescriptor",
    "ObjectDN
| startswith": "CN=AdminSDHolder,CN=System,*"
  },
  "condition": "selection"
}

False Positives

  • Unknown

Field Validations

Loading…

Comments (0)

Loading comments...