Addition of SID History to Active Directory Object

 Original Source: [Sigma source]
Title: Addition of SID History to Active Directory Object
Status: stable
Description:An attacker can use the SID history attribute to gain additional privileges.
References:
  -https://adsecurity.org/?p=1772
Author: Thomas Patzke, @atc_project (improvements)
Date: 2017-02-19
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1134.005'
Logsource:
  • product: windows
  • service: security
Detection:
  selection1:
    EventID:
      -'4765'
      -'4766'

  selection2:
    EventID: '4738'
  selection3:
    SidHistory:
      -'-'
      -'%%1793'

  filter_null:
    SidHistory: 'None'
  condition:selection1 or (selection2 and not selection3 and not filter_null)
Falsepositives:
  -Migration of an account into a new domain
Level: medium