DSRM Account Abuse

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This query detects an abuse of the DSRM account in order to maintain persistence and access to the organization's Active Directory. Ref: https://adsecurity.org/?p=1785

Attribute Value
Type Analytic Rule
Solution Standalone Content
ID 979c42dd-533e-4ede-b18b-31a84ba8b3d6
Severity High
Kind Scheduled
Tactics Persistence
Techniques T1098
Required Connectors SecurityEvents
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules