Suspicious dNSHostName attribute change to DC name
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
ATT&CK Tactic
Privilege Escalation (TA0004), Persistence (TA0003)
ATT&CK Technique
Account Manipulation (T1098), Valid Accounts: Domain Accounts (T1078.002)
Severity
Medium
Description
The dNSHostName attribute of a machine account was changed to a Domain Controller server name.
Attacker's Goals
Elevate privileges from standard domain user to domain admin.
Investigative actions
Check if the domain controller is patched or vulnerable to the attack.
Check if any associated TGTs or service tickets were granted.
Follow actions by the account and if it performed a DCSync.
Was this helpful?
