Rogue Domain Controller
Adversaries may register a rogue Domain Controller to enable manipulation of Active Directory data. DCShadow may be used to create a rogue Domain Controller (DC). DCShadow is a method of manipulating Active Directory (AD) data, including objects and schemas, by registering (or reusing an inactive registration) and simulating the behavior of a DC. (Citation: DCShadow Blog) Once registered, a rogue DC may be able to inject and replicate changes into AD infrastructure for any domain object, includi...
BY SOURCE
PROCEDURES (7)
Auto-extracted: 2 detections for persist
Auto-extracted: 1 detections for service monitoring
Auto-extracted: 1 detections for authentication monitoring
Auto-extracted: 1 detections for general monitoring
Auto-extracted: 1 detections for credential
Auto-extracted: 1 detections for credential
Auto-extracted: 1 detections for credential