Analytics BIOC Medium

Suspicious dNSHostName attribute change to DC name

The dNSHostName attribute of a machine account was changed to a Domain Controller server name.

Module:
Identity Analytics
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098) Valid Accounts: Domain Accounts (T1078.002)
Attacker's goals:

Elevate privileges from standard domain user to domain admin.

Investigative actions:

Check if the domain controller is patched or vulnerable to the attack. Check if any associated TGTs or service tickets were granted. Follow actions by the account and if it performed a DCSync.

Test period:
N/A (single event)
Deduplication:
1 Day