Windows Security Event DCShadow Indicators via New Service Principal Name GC/

Flags Windows Security events where a servicePrincipalName starting with "GC/" is created, consistent with DCShadow-style SPN registration.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Ilyas Ochkov, oscd.community, Chakib Gzenayi (@Chak092), Hosni Mribah (SigmaHQ), DRL 1.1
Published
2019-10-25
Updated
2026-07-31

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags potential DCShadow activity by looking for new or modified service principal name (SPN) entries that start with "GC/". An attacker using DCShadow techniques may create SPNs to influence how Directory Service components authenticate or interact. The detection relies on Windows Security logs for SPN-related changes, specifically Event ID 4742 and Event IDs 5136/5137/5138/5139/5141 with LDAP attribute servicePrincipalName containing values beginning with "GC/".

Related detections2 linkedT1207 — drag to rearrange
Suspicious Modification of dMSA Managed Account Link Attributes
Windows Security Event Add/Remove Computer Account (4741/4743)
Windows Security Event DCShadow Indicators via New Service Principal Name GC/
Pivot detection · T1207 · 2 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.