DMSA Link Attributes Modified

 Original Source: [Sigma source]
Title: DMSA Link Attributes Modified
Status: experimental
Description:Detects modification of dMSA link attributes (msDS-ManagedAccountPrecededByLink) via PowerShell scripts. This command line pattern could be an indicator an attempt to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025.
References:
  -https://www.akamai.com/blog/security-research/abusing-bad-successor-for-privilege-escalation-in-active-directory
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-05-24
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.initial-access'
  • -'attack.stealth'
  • -'attack.t1078.002'
  • -'attack.t1098'
Logsource:
  • category: ps_script
  • product: windows
Detection:
  selection:
    ScriptBlockText|contains|all:
      -'.Put("msDS-ManagedAccountPrecededByLink'
      -'CN='

  condition:selection
Falsepositives:
  -Legitimate administrative tasks modifying these attributes.
Level: low