Cross-source coverage
T1078.002 / ATT&CK
Valid Accounts: Domain Accounts
35 rules across 5 sources.
From MITRE ATT&CK 19.2
Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.
Adversaries may compromise domain accounts, some with a high level of privileges, through various means such as OS Credential Dumping or password reuse, allowing access to privileged resources of the domain.
- Tactics
- Stealth · Persistence · Privilege Escalation · Initial Access
- Platforms
- ESXi · Linux · macOS · Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLlinux:syslogmacos:unifiedlogesxi:vpxdesxi:hostd
How MITRE says to detect it DET0210
Abuse of Domain Accounts
Windows Analytic 0590
Detection of suspicious logon behavior using valid domain accounts across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations.
WinEventLog:SecurityEventCode=4624, 4625, 4768, 4769WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=3, 22
Linux Analytic 0591
Use of domain accounts via sssd or winbind for logon activity outside of typical patterns, especially on sensitive systems or with lateral movement tools.
auditd:SYSCALLpam_authenticate, sshdlinux:syslogsssd / sudo logs
macOS Analytic 0592
Domain logins using network accounts or mobile accounts via Open Directory or Active Directory plugins, especially outside business hours or on atypical endpoints.
macos:unifiedloglog show --predicate 'eventMessage contains "Authentication"'
ESXi Analytic 0593
Login to vSphere or ESXi hosts using domain accounts, especially those associated with vpxuser or unexpected group memberships.
esxi:vpxd/var/log/vmware/vpxd.logesxi:hostd/var/log/hostd.log
elastic/detection-rules
15 rules| Detection | Severity | Format |
|---|---|---|
| AdminSDHolder Backdoor | High | Elastic TOML |
| AdminSDHolder SDProp Exclusion Added | High | Elastic TOML |
| Delegated Managed Service Account Modification by an Unusual User | High | Elastic TOML |
| dMSA Account Creation by an Unusual User | High | Elastic TOML |
| First Time Seen Account Performing DCSync | High | Elastic TOML |
| Potential Privileged Escalation via SamAccountName Spoofing | High | Elastic TOML |
| Remote Computer Account DnsHostName Update | High | Elastic TOML |
| Access to a Sensitive LDAP Attribute | Medium | Elastic TOML |
| Kerberos Pre-authentication Disabled for User | Medium | Elastic TOML |
| Potential Credential Access via DCSync | Medium | Elastic TOML |
+ 5 more from elastic/detection-rules → showing the 10 highest-severity
SigmaHQ/sigma
7 rules| Detection | Severity | Format |
|---|---|---|
| Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure | High | Sigma |
| DMSA Service Account Created in Specific OUs - PowerShell | Medium | Sigma |
| msDS-ManagedAccountPrecededByLink Attribute Modified | Medium | Sigma |
| New DMSA Service Account Created in Specific OUs | Medium | Sigma |
| New MsDS-DelegatedManagedServiceAccount (DMSA) Object Created | Medium | Sigma |
| Admin User Remote Logon | Low | Sigma |
| DMSA Link Attributes Modified | Low | Sigma |
splunk/security_content
6 rules| Detection | Severity | Format |
|---|---|---|
| Detect Excessive Account Lockouts From Endpoint | Undefined | SPL |
| Suspicious Computer Account Name Change | Undefined | SPL |
| Suspicious Kerberos Service Ticket Request | Undefined | SPL |
| Suspicious Ticket Granting Ticket Request | Undefined | SPL |
| Windows Group Policy Object Created | Undefined | SPL |
| Windows PowerView AD Access Control List Enumeration | Undefined | SPL |
Wazuh Core Ruleset
4 rulesBert-JanP/Hunting-Queries-Detection-Rules
3 rules| Detection | Severity | Format |
|---|---|---|
| MITRE ATT&CK Mapping | Undefined | KQL |
| Multiple Sensitive Group Additions From Commandline | Undefined | KQL |
| User added to sensitive group | Undefined | KQL |