Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / THREAT HUNT / ACTIVE DIRECTORY

Hunt Matrix


Active Directory Attack Detection Matrix

TechniquePrimary LogsCritical Event IDsKey Detection SignalTypical Tool
KerberoastingSecurity4769High volume TGS requestsRubeus
ASREP RoastingSecurity4768AS-REQ without preauthGetNPUsers
TimeroastingSecurity4769Timing analysis anomaliesCustom tooling
LSASS DumpingSysmon / Security10 / 4688LSASS handle accessMimikatz
SAM DumpingSecurity4663SAM hive readsecretsdump
LSA SecretsSecurity4663SECURITY hive accesssecretsdump
NTDS DumpingSecurity4662NTDS replicationntdsutil
DCSyncSecurity4662Replication rights abuseMimikatz
DCShadowSecurity5137Rogue DC registrationmimikatz
Unconstrained DelegationSecurity4769TGT forwardingRubeus
Constrained DelegationSecurity4769S4U2Proxy usageRubeus
RBCDSecurity5136msDS-AllowedToActOnBehalfOfPowermad
NTLM RelaySecurity4624NTLM logonsntlmrelayx
Kerberos RelaySecurity4769Kerberos relay attemptskrbrelayx
LDAP RelaySecurity4662LDAP object modificationntlmrelayx
SMB RelaySecurity5140ADMIN$ share accessntlmrelayx
Golden CertificateSecurity4886Certificate misuseCertipy
ADCS ESC1Security4887Misconfigured templateCertipy
ADCS ESC2Security4887SAN abuseCertipy
ADCS ESC3Security4887Enrollment agent abuseCertipy
ADCS ESC4Security4887Certificate mapping abuseCertipy
Golden TicketSecurity4769Forged TGT usageMimikatz
Silver TicketSecurity4769Forged service ticketMimikatz
Pass the HashSecurity4624NTLM authenticationCrackMapExec
Pass the TicketSecurity4769Ticket reuseRubeus
Overpass the HashSecurity4768NTLM → KerberosMimikatz
GenericAll AbuseSecurity5136ACL modificationPowerView
WriteDACL AbuseSecurity5136DACL changesPowerView
Shadow CredentialsSecurity5136KeyCredentialLink setWhisker
LAPS AbuseSecurity4662LAPS password readCrackMapExec
GMSA ExtractionSecurity4662gMSA password retrievalgMSADumper
GPP PasswordsFile accessSYSVOL readcpassword retrievalPowerSploit
LDAP EnumerationSecurity4662LDAP queriesldapsearch
SMB EnumerationSecurity5140Share enumerationsmbclient
RID CyclingSecurity4624Sequential RID queriesenum4linux
Password SprayingSecurity4625Failed logons across accountsCrackMapExec
SPN EnumerationSecurity4662servicePrincipalName queriesPowerView
Domain Trust EnumerationSecurity4662trustedDomain queriesnltest
DNS EnumerationDNS logsDNS querieszone discoverydnsrecon
BloodHound CollectionSysmon1SharpHound executionSharpHound
Printer BugSecurity4624Forced authSpoolSample
PetitPotamSecurity4624EFSRPC coercionPetitPotam
DFSCoerceSecurity4624DFS RPC coercionDFSCoerce
ShadowCoerceSecurity4624MS-FSRVP coercionShadowCoerce
ADIDNS PoisoningDNSDNS writesmalicious recordPowermad
DNSAdmins DLLSecurity7045DNS service abusednscmd
DNS Zone TransferDNSAXFRunauthorized zone transferdig
xp_cmdshellSQL logsxp_cmdshell executionOS command executionsqlcmd
Linked Server AbuseSQL logsremote executionlateral SQL pivotPowerUpSQL
Golden SAMLADFS logstoken issuanceforged SAMLADFSDump
GPO ModificationSecurity5136GPO changePowerView
GPO CreationSecurity5137new GPO createdSharpGPO
GPO Link AbuseSecurity5136GPO link changePowerView
SYSVOL TamperingFile logsSYSVOL writesmalicious scriptmanual
SMBExecSecurity7045service installimpacket
WMIExecSysmon1wmiprvse spawning shellimpacket
PsExecSecurity7045PSEXESVC serviceSysinternals
DCOMExecSysmon1dllhost spawning shellimpacket
WinRM ExecWinRM logs91remote PS sessionEvil-WinRM