DC Machine Account Network Logon from Non-DC Source IP
Description
Detects a Domain Controller machine account authenticating from a source IP that is not a known Domain Controller. DC machine accounts should only authenticate locally or from other DCs during replication operations. Any logon event for a DC account from a workstation or non-DC host is anomalous and indicates one of the following:
- Silver Ticket: attacker forged a Kerberos TGS for a DC machine account without requesting a TGT
- Pass-the-Ticket: attacker is replaying a captured DC machine account TGS from a non-DC host
- Overpass-the-Hash: attacker converted a stolen DC machine account hash into a Kerberos ticket and is authenticating from a non-DC host
- Exploitation of certain vulnerabilities such as CVE-2026-54121 (Certighost): attacker obtained a DC certificate via ADCS CDC-chase abuse, authenticates via PKINIT as the DC from their own host, then performs DCSync
Query · sigma
selection: EventID: 4624 TargetUserName|endswith: $ TargetUserName|expand: '%dc_machine_accounts%' filter_main_dc_source: IpAddress|expand: '%dc_ip_addresses%' filter_main_loopback: - IpAddress: - 127.0.0.1 - ::1 - ::ffff:127.0.0.1 - '-' - IpAddress|startswith: 'fe80:' condition: selection and not 1 of filter_main_*
Known false positives
- Unlikely if %dc_machine_accounts% and %dc_ip_addresses% are correctly populated.