For the complete documentation index, see llms.txt. This page is also available as Markdown.

Possible Distributed File System Namespace Management (DFSNM) abuse

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Forced Authentication (T1187), Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay (T1557.001)

Severity

High

Description

A possible abuse of Distributed File System Namespace Management (DFSNM).

Attacker's Goals

  • An attacker can abuse the Distributed File System Namespace Management protocol to coerce an authentication from a DC.

  • This authentication can later be used for obtaining a DC certificate for DCSync.

Investigative actions

  • Check for a suspicious process on the initiator.

  • Check if the source host is a vulnerability scanner.

  • Look for unusual AD CS certificate requests.

  • Check for possible DCSync alerts.

Was this helpful?