- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
Classification:
attack
Tactic:
Technique:
Detects an instance where a user or process modifies the Discretionary Access Control List (DACL) of an Active Directory (AD) object.
This detection monitors Windows Security event logs for occurrences of Event ID 4662 (An operation was performed on an object) with specific indicators of DACL modifications.
DACL modifications in Active Directory can be used to grant specific permissions to accounts, allowing attackers to maintain persistence even after credentials are changed. This technique is particularly concerning when applied to high-value objects like domain controllers or administrative groups.
{{host}}
domain controller that recorded the DACL modification event.SubjectUserName
field.ObjectName
field.