You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Rules: Powerview Add-DomainObjectAcl DCSync AD Extend Right
Description
Backdooring domain object to grant the rights associated with DCSync to a regular user or machine account using Powerview\Add-DomainObjectAcl DCSync Extended Right cmdlet, will allow to re-obtain the pwd hashes of any user/computer
Additional Details
Detail
Value
Type
Templated Match
Category
Unknown/Other
Apply Risk to Entities
device_hostname, user_username
Signal Name
Powerview Add-DomainObjectAcl DCSync AD Extend Right
Summary Expression
Detected Powerview Add-DomainObjectAcl DCSync AD Extend Right use on {{device_hostname}}