Forum Discussion
Tali Ash
Jul 24, 2018Microsoft
Azure ATP brings you 2 new preview detections on DcShadow attack
A domain controller shadow (DCShadow) attack is an attack designed to change directory objects using malicious replication. This attack can be performed from any machine by creating a rogue domain controller using a replication process.
DCShadow uses RPC and LDAP to:
- Register the machine account as a domain controller (using domain admin rights), and
- Perform replication (using the granted replication rights) over DRSUAPI and send changes to directory objects.
Azure ATP detects the attack by 2 security alerts:
- Suspicious domain controller promotion (potential DCShadow attack)
- Suspicious replication request (potential DCShadow attack)
Stay tuned. Your feedback is welcome.
No RepliesBe the first to reply