Windows Security: Detects DCSync Extended Right ACE Changes (EventID 5136) via Powerview Add-DomainObjectAcl
Flags directory ACL changes (EventID 5136) that include DCSync extended right GUIDs in ntSecurityDescriptor for DNS objects.
FreeUnreviewedSigmahighv1
windows-security-detects-dcsync-extended-right-ace-changes-eventid-5136-via-powe-2c99737c
title: "Windows Security: Detects DCSync Extended Right ACE Changes (EventID 5136) via Powerview Add-DomainObjectAcl"
id: f97a6de1-56fa-40fc-9442-f971fe610e14
status: test
description: This rule identifies Windows Security auditing events (Event ID 5136) where an LDAP security descriptor (ntSecurityDescriptor) change includes specific GUIDs associated with the DCSync extended right ACE. Attackers can abuse such ACL modifications to grant replication-related permissions to non-privileged accounts, enabling directory abuse. The detection relies on Security log telemetry for directory service object changes and matches the GUIDs present in the modified security descriptor attributes, filtered to DNS-related object classes.
references:
- https://twitter.com/menasec1/status/1111556090137903104
- https://www.specterops.io/assets/resources/an_ace_up_the_sleeve.pdf
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_account_backdoor_dcsync_rights.yml
author: Samir Bousseaden, Roberto Rodriguez @Cyb3rWard0g, oscd.community, Tim Shelton, Maxence Fossat, Huntrule Team
date: 2019-04-03
modified: 2022-08-16
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1098
logsource:
product: windows
service: security
definition: 'Requirements: The "Audit Directory Service Changes" logging policy must be configured in order to receive events. Audit events are generated only for objects with configured system access control lists (SACLs). Audit events are generated only for objects with configured system access control lists (SACLs) and only when accessed in a manner that matches their SACL settings. This policy covers the following events ids - 5136, 5137, 5138, 5139, 5141. Note that the default policy does not cover User objects. For that a custom AuditRule need to be setup (See https://github.com/OTRF/Set-AuditRule)'
detection:
selection:
EventID: 5136
AttributeLDAPDisplayName: ntSecurityDescriptor
AttributeValue|contains:
- 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2
- 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2
- 89e95b76-444d-4c62-991a-0facbeda640c
filter_main_dns_object_class:
ObjectClass:
- dnsNode
- dnsZoneScope
- dnsZone
condition: selection and not 1 of filter_main_*
falsepositives:
- New Domain Controller computer account, check user SIDs within the value attribute of event 5136 and verify if it's a regular user or DC computer account.
level: high
license: DRL-1.1
related:
- id: 2c99737c-585d-4431-b61a-c911d86ff32f
type: derived
What it detects
This rule identifies Windows Security auditing events (Event ID 5136) where an LDAP security descriptor (ntSecurityDescriptor) change includes specific GUIDs associated with the DCSync extended right ACE. Attackers can abuse such ACL modifications to grant replication-related permissions to non-privileged accounts, enabling directory abuse. The detection relies on Security log telemetry for directory service object changes and matches the GUIDs present in the modified security descriptor attributes, filtered to DNS-related object classes.
Known false positives
- New Domain Controller computer account, check user SIDs within the value attribute of event 5136 and verify if it's a regular user or DC computer account.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.