Analytics BIOC
Medium
✕
Suspicious dNSHostName attribute change to DC name
The dNSHostName attribute of a machine account was changed to a Domain Controller server name.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098) Valid Accounts: Domain Accounts (T1078.002)
Attacker's goals:
Elevate privileges from standard domain user to domain admin.
Investigative actions:
Check if the domain controller is patched or vulnerable to the attack. Check if any associated TGTs or service tickets were granted. Follow actions by the account and if it performed a DCSync.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day