Cross-source coverage

T1078.002 / ATT&CK

Valid Accounts: Domain Accounts

35 rules across 5 sources.

From MITRE ATT&CK 19.2

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Adversaries may compromise domain accounts, some with a high level of privileges, through various means such as OS Credential Dumping or password reuse, allowing access to privileged resources of the domain.

Platforms
ESXi · Linux · macOS · Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLlinux:syslogmacos:unifiedlogesxi:vpxdesxi:hostd

How MITRE says to detect it DET0210

Abuse of Domain Accounts

Windows Analytic 0590

Detection of suspicious logon behavior using valid domain accounts across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations.

  • WinEventLog:Security EventCode=4624, 4625, 4768, 4769
  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=3, 22

Linux Analytic 0591

Use of domain accounts via sssd or winbind for logon activity outside of typical patterns, especially on sensitive systems or with lateral movement tools.

  • auditd:SYSCALL pam_authenticate, sshd
  • linux:syslog sssd / sudo logs

macOS Analytic 0592

Domain logins using network accounts or mobile accounts via Open Directory or Active Directory plugins, especially outside business hours or on atypical endpoints.

  • macos:unifiedlog log show --predicate 'eventMessage contains "Authentication"'

ESXi Analytic 0593

Login to vSphere or ESXi hosts using domain accounts, especially those associated with vpxuser or unexpected group memberships.

  • esxi:vpxd /var/log/vmware/vpxd.log
  • esxi:hostd /var/log/hostd.log

elastic/detection-rules

15 rules
Detection Severity Format
AdminSDHolder Backdoor High Elastic TOML
AdminSDHolder SDProp Exclusion Added High Elastic TOML
Delegated Managed Service Account Modification by an Unusual User High Elastic TOML
dMSA Account Creation by an Unusual User High Elastic TOML
First Time Seen Account Performing DCSync High Elastic TOML
Potential Privileged Escalation via SamAccountName Spoofing High Elastic TOML
Remote Computer Account DnsHostName Update High Elastic TOML
Access to a Sensitive LDAP Attribute Medium Elastic TOML
Kerberos Pre-authentication Disabled for User Medium Elastic TOML
Potential Credential Access via DCSync Medium Elastic TOML

+ 5 more from elastic/detection-rules → showing the 10 highest-severity

SigmaHQ/sigma

7 rules
Detection Severity Format
Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure High Sigma
DMSA Service Account Created in Specific OUs - PowerShell Medium Sigma
msDS-ManagedAccountPrecededByLink Attribute Modified Medium Sigma
New DMSA Service Account Created in Specific OUs Medium Sigma
New MsDS-DelegatedManagedServiceAccount (DMSA) Object Created Medium Sigma
Admin User Remote Logon Low Sigma
DMSA Link Attributes Modified Low Sigma

splunk/security_content

6 rules
Detection Severity Format
Detect Excessive Account Lockouts From Endpoint Undefined SPL
Suspicious Computer Account Name Change Undefined SPL
Suspicious Kerberos Service Ticket Request Undefined SPL
Suspicious Ticket Granting Ticket Request Undefined SPL
Windows Group Policy Object Created Undefined SPL
Windows PowerView AD Access Control List Enumeration Undefined SPL

Wazuh Core Ruleset

4 rules
Detection Severity Format
User: \ logged using Remote Desktop Connection (RDP) from loopback address, possible exploit over reverse tunneling using stolen credentials. · win.eventdata.logonType = 10, win.eventdata.ipAddress = ::1|127\.0\.0\.1 Critical Wazuh XML
Successful Remote Logon Detected - User:\ - NTLM authentication, possible pass-the-hash attack - Possible RDP connection. Verify that is allowed to perform RDP connections · win.eventdata.workstationName = .+ Medium Wazuh XML
Successful Remote Logon Detected - User:\ - NTLM authentication, possible pass-the-hash attack. · win.eventdata.authenticationPackageName = NTLM Medium Wazuh XML
User: \ logged using Remote Desktop Connection (RDP) from ip:. · win.eventdata.logonType = 10 Low Wazuh XML

Bert-JanP/Hunting-Queries-Detection-Rules

3 rules
Detection Severity Format
MITRE ATT&CK Mapping Undefined KQL
Multiple Sensitive Group Additions From Commandline Undefined KQL
User added to sensitive group Undefined KQL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.