Vulnerable Netlogon Secure Channel Connection Allowed

 Original Source: [Sigma source]
Title: Vulnerable Netlogon Secure Channel Connection Allowed
Status: test
Description:Detects that a vulnerable Netlogon secure channel connection was allowed, which could be an indicator of CVE-2020-1472.
References:
  -https://support.microsoft.com/en-us/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc
Author: NVISO
Date: 2020-09-15
modified:2022-12-25
Tags:
  • -'attack.privilege-escalation'
  • -'attack.t1548'
Logsource:
  • product: windows
  • service: system
Detection:
  selection:
    Provider_Name: 'NetLogon'
    EventID: '5829'
  condition:selection
Falsepositives:
  -Unknown
Level: high