Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0008 ✕ technique: T1078 ✕
Download CSV Show ATT&CK heatmapAbnormal User Login to Domain Controller Informational Identity Analytics 4 variations
A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Lateral Movement (TA0008) Privilege Escalation (TA0004)ATT&CK techniques: Valid Accounts (T1078) Use Alternate Authentication Material (T1550)Required data: XDR AgentAttacker's goals: A malicious user may attempt to access a domain controller to access and control Active Directory.Investigative actions: Ensure that the user is not a Domain Admin account. By default, Administrator groups have permission to access the domain controller. Check if the user is a service account that accesses a domain controller as part of its normal behavior. Verify that the user is not authenticating to group policy.Variations
Rare RDP User Login to Domain Controller by an Abnormal Department
Medium overridden
A user account has successfully interactively logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise. overridden
Abnormal RDP User Login to Domain Controller
Low overridden
A user account has successfully interactively logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise. overridden
RDP User Login to Domain Controller
Informational overridden
A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise. overridden
Abnormal User Login to Domain Controller by an Abnormal Department
Informational overridden
A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise. overridden