Password Change on Directory Service Restore Mode (DSRM) Account

 Original Source: [Sigma source]
Title: Password Change on Directory Service Restore Mode (DSRM) Account
Status: stable
Description:Detects potential attempts made to set the Directory Services Restore Mode administrator password. The Directory Service Restore Mode (DSRM) account is a local administrator account on Domain Controllers. Attackers may change the password in order to obtain persistence.
References:
  -https://adsecurity.org/?p=1714
  -https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4794
Author: Thomas Patzke
Date: 2017-02-19
modified:2020-08-23
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1098'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '4794'
  condition:selection
Falsepositives:
  -Initial installation of a domain controller.
Level: high