Analytics BIOC
Low
✕
Suspicious sAMAccountName change
The name of a machine account was changed to a sAMAccountName with a missing trailing dollar sign.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098) Valid Accounts (T1078)
Attacker's goals:
Elevate privileges from standard domain user to domain admin.
Investigative actions:
Check if the domain controller is patched or vulnerable to the attack. Check if any associated TGTs or service tickets were granted. Follow actions by the account and if it performed a DCSync.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Suspicious sAMAccountName change to DC hostname Medium (parent: Low)