Renamed Computer Account Renamed Without a Trailing $ - CVE-2021-42278/42287 (via security)
- Product
- windows
- Service
- security
- Author
- HuntRule
- Published
- 2026-06-22
- Updated
- 2026-08-28
ATT&CK techniques
Persistence → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule detects spoof the SAM account name of a a domain controller in order to impersonate it. Vulnerability comes from that computer accounts should have a trailing $ in their name (i.e. sAMAccountName attribute) but no validation process existed until the patch was released. During the offensive phase, attacker will create and rename the sAMAccountName of a computer account to look like the one of a domain controller. Once the attack is done, attacker will rollback the sAMAccountName to its original name.
Reporting behind it
- attack.mitre.orghttps://attack.mitre.org/techniques/T1098/
- attack.mitre.orghttps://attack.mitre.org/techniques/T1036/
- attack.mitre.orghttps://attack.mitre.org/techniques/T1068/
- exploit.phhttps://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html
- thehacker.recipeshttps://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing
- support.microsoft.comhttps://support.microsoft.com/en-us/topic/kb5008380-authentication-updates-cve-2021-42287-9dafac11-e0d0-4cb8-959a-143bd0201041
- github.comhttps://github.com/WazeHell/sam-the-admin
- github.comhttps://github.com/cube0x0/noPac
- github.comhttps://github.com/ly4k/Pachine
- cloudbrothers.infohttps://cloudbrothers.info/en/exploit-kerberos-samaccountname-spoofing/
- medium.comhttps://medium.com/@mvelazco/hunting-for-samaccountname-spoofing-cve-2021-42287-and-domain-controller-impersonation-f704513c8a45
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
Unlock this rule to view and copy it
The detection logic is included with a plan. Everything else — context, mappings and implementation details — stays free on this page.
Signing in gives you 3 unlocks to spend on any rule in the library. No card, and they do not expire.
Also included
Unlocked rules convert on this page — to Splunk SPL or Splunk — Raw Index SPL or Microsoft Sentinel KQL or Microsoft Sentinel ASIM ASIM KQL or Microsoft Defender XDR KQL or Elastic Security KQL or Elastic Security Lucene or Elastic Security ES|QL or CrowdStrike Falcon CQL or SentinelOne PowerQuery or Palo Alto Cortex XDR XQL or Carbon Black Cloud Platform Search or Carbon Black EDR Process Search or Google Security Operations UDM Search or IBM QRadar AQL or Sumo Logic Cloud SIEM Rules expression or Rapid7 InsightIDR LEQL or Graylog Search or OpenSearch Lucene or OpenSearch PPL PPL or Grafana Loki LogQL or SQLite SQL or Zircolite SQLite — with the log-source profile the engine picked, the field map it used, and everything it could not express. Converting a rule you have unlocked costs no further credit.