For the complete documentation index, see llms.txt. This page is also available as Markdown.

Abnormal User Login to Domain Controller

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detection Modules

Identity Analytics

ATT&CK Tactic

Lateral Movement (TA0008), Privilege Escalation (TA0004)

ATT&CK Technique

Valid Accounts (T1078), Use Alternate Authentication Material (T1550)

Severity

Informational

Description

A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise.

Attacker's Goals

A malicious user may attempt to access a domain controller to access and control Active Directory.

Investigative actions

  • Ensure that the user is not a Domain Admin account. By default, Administrator groups have permission to access the domain controller.

  • Check if the user is a service account that accesses a domain controller as part of its normal behavior.

  • Verify that the user is not authenticating to group policy.

Variations

Rare RDP User Login to Domain Controller by an Abnormal Department

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008), Privilege Escalation (TA0004)

ATT&CK Technique

Valid Accounts (T1078), Use Alternate Authentication Material (T1550)

Severity

Medium

Description

A user account has successfully interactively logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise.

Attacker's Goals

A malicious user may attempt to access a domain controller to access and control Active Directory.

Investigative actions

  • Ensure that the user is not a Domain Admin account. By default, Administrator groups have permission to access the domain controller.

  • Check if the user is a service account that accesses a domain controller as part of its normal behavior.

  • Verify that the user is not authenticating to group policy.

Abnormal RDP User Login to Domain Controller

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008), Privilege Escalation (TA0004)

ATT&CK Technique

Valid Accounts (T1078), Use Alternate Authentication Material (T1550)

Severity

Low

Description

A user account has successfully interactively logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise.

Attacker's Goals

A malicious user may attempt to access a domain controller to access and control Active Directory.

Investigative actions

  • Ensure that the user is not a Domain Admin account. By default, Administrator groups have permission to access the domain controller.

  • Check if the user is a service account that accesses a domain controller as part of its normal behavior.

  • Verify that the user is not authenticating to group policy.

RDP User Login to Domain Controller

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008), Privilege Escalation (TA0004)

ATT&CK Technique

Valid Accounts (T1078), Use Alternate Authentication Material (T1550)

Severity

Informational

Description

A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise.

Attacker's Goals

A malicious user may attempt to access a domain controller to access and control Active Directory.

Investigative actions

  • Ensure that the user is not a Domain Admin account. By default, Administrator groups have permission to access the domain controller.

  • Check if the user is a service account that accesses a domain controller as part of its normal behavior.

  • Verify that the user is not authenticating to group policy.

Abnormal User Login to Domain Controller by an Abnormal Department

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008), Privilege Escalation (TA0004)

ATT&CK Technique

Valid Accounts (T1078), Use Alternate Authentication Material (T1550)

Severity

Informational

Description

A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise.

Attacker's Goals

A malicious user may attempt to access a domain controller to access and control Active Directory.

Investigative actions

  • Ensure that the user is not a Domain Admin account. By default, Administrator groups have permission to access the domain controller.

  • Check if the user is a service account that accesses a domain controller as part of its normal behavior.

  • Verify that the user is not authenticating to group policy.

Was this helpful?