Windows Security: Detects DCSync Extended Right ACE Changes (EventID 5136) via Powerview Add-DomainObjectAcl

Flags directory ACL changes (EventID 5136) that include DCSync extended right GUIDs in ntSecurityDescriptor for DNS objects.

FreeUnreviewedSigmahighv1
title: "Windows Security: Detects DCSync Extended Right ACE Changes (EventID 5136) via Powerview Add-DomainObjectAcl"
id: f97a6de1-56fa-40fc-9442-f971fe610e14
status: test
description: This rule identifies Windows Security auditing events (Event ID 5136) where an LDAP security descriptor (ntSecurityDescriptor) change includes specific GUIDs associated with the DCSync extended right ACE. Attackers can abuse such ACL modifications to grant replication-related permissions to non-privileged accounts, enabling directory abuse. The detection relies on Security log telemetry for directory service object changes and matches the GUIDs present in the modified security descriptor attributes, filtered to DNS-related object classes.
references:
  - https://twitter.com/menasec1/status/1111556090137903104
  - https://www.specterops.io/assets/resources/an_ace_up_the_sleeve.pdf
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_account_backdoor_dcsync_rights.yml
author: Samir Bousseaden, Roberto Rodriguez @Cyb3rWard0g, oscd.community, Tim Shelton, Maxence Fossat, Huntrule Team
date: 2019-04-03
modified: 2022-08-16
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.t1098
logsource:
  product: windows
  service: security
  definition: 'Requirements: The "Audit Directory Service Changes" logging policy must be configured in order to receive events. Audit events are generated only for objects with configured system access control lists (SACLs). Audit events are generated only for objects with configured system access control lists (SACLs) and only when accessed in a manner that matches their SACL settings. This policy covers the following events ids - 5136, 5137, 5138, 5139, 5141. Note that the default policy does not cover User objects. For that a custom AuditRule need to be setup (See https://github.com/OTRF/Set-AuditRule)'
detection:
  selection:
    EventID: 5136
    AttributeLDAPDisplayName: ntSecurityDescriptor
    AttributeValue|contains:
      - 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2
      - 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2
      - 89e95b76-444d-4c62-991a-0facbeda640c
  filter_main_dns_object_class:
    ObjectClass:
      - dnsNode
      - dnsZoneScope
      - dnsZone
  condition: selection and not 1 of filter_main_*
falsepositives:
  - New Domain Controller computer account, check user SIDs within the value attribute of event 5136 and verify if it's a regular user or DC computer account.
level: high
license: DRL-1.1
related:
  - id: 2c99737c-585d-4431-b61a-c911d86ff32f
    type: derived

What it detects

This rule identifies Windows Security auditing events (Event ID 5136) where an LDAP security descriptor (ntSecurityDescriptor) change includes specific GUIDs associated with the DCSync extended right ACE. Attackers can abuse such ACL modifications to grant replication-related permissions to non-privileged accounts, enabling directory abuse. The detection relies on Security log telemetry for directory service object changes and matches the GUIDs present in the modified security descriptor attributes, filtered to DNS-related object classes.

Known false positives

  • New Domain Controller computer account, check user SIDs within the value attribute of event 5136 and verify if it's a regular user or DC computer account.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.