SAM Name Change CVE-2021-42278

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


The following query detects possible CVE-2021-42278 exploitation by finding changes of device names in the network using Microsoft Defender for Identity.

Attribute Value
Type Hunting Query
Solution Microsoft Defender XDR
ID 1299962c-804e-459a-8d3d-41d68bc45ba2
Tactics PrivilegeEscalation, Vulnerability
Required Connectors MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
IdentityDirectoryEvents ActionType == "SAM Account Name changed" ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Microsoft Defender XDR