Skip to content

[Meta] Explore Detection Opportunities on Active Directory Object Ownership and Privilege Assignment #3522

@w0rk3r

Description

@w0rk3r

Parent Epic

https://github.com/elastic/ia-trade-team/issues/276

Summary

Explore how attackers abuse object ownership issues for privilege escalation, lateral movement, and persistence.

  • Read the whitepaper and decide on scenarios that can be simulated with low to medium effort
  • Document and do it
  • Ship detections and hunting queries
  • STRETCH: Ingest Pipelines to parse basic SDDL

Resources:

PRs

  • TBD

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions