Skip to main content
ID Academia

MITRE ATT&CK matrix for AD

Every attack on this site → its MITRE technique → which events reveal it → a SIEM detection rule idea.

Go to attack cards

Discovery

TA0007

  • BloodHound / SharpHoundT1087.002

    Mass LDAP queries

    Rule idea (pseudo-query)LDAP queries > N/min from one host (Event 1644)

Credential Access

TA0006

  • AS-REP RoastingT1558.004

    TGT without pre-auth

    Rule idea (pseudo-query)EventID=4768 AND PreAuthType=0
  • KerberoastingT1558.003

    RC4 service ticket for a user account

    Rule idea (pseudo-query)EventID=4769 AND TicketEncryptionType=0x17 AND ServiceName!="*$"
  • NTLM RelayT1557.001

    IP does not match the workstation

    Rule idea (pseudo-query)EventID=4624 AND AuthenticationPackageName=NTLM AND IpAddress NOT IN known_hosts(WorkstationName)
  • DCSyncT1003.006

    Replication from a non-DC account

    Rule idea (pseudo-query)EventID=4662 AND Properties CONTAINS "1131f6aa" AND SubjectUserName!="*$"
  • Password SprayingT1110.003

    One IP, many users

    Rule idea (pseudo-query)EventID IN (4625,4771) | distinct TargetUserName by IpAddress > 10 in 30m

Privilege Escalation

TA0004

  • AD CS (ESC1)T1649

    Certificate issued for another identity

    Rule idea (pseudo-query)EventID=4887 AND RequesterName != SubjectName
  • Delegation AbuseT1134.001

    S4U / delegation in use

    Rule idea (pseudo-query)EventID=4769 AND TransitedServices!="-"

Lateral Movement

TA0008

  • Pass-the-HashT1550.002

    NTLM logon without a real password

    Rule idea (pseudo-query)EventID=4624 AND (LogonType=9 OR (LogonType=3 AND LmPackageName="NTLM V2" AND KeyLength=0))

Persistence

TA0003

  • Golden TicketT1558.001

    Service ticket with no issued TGT

    Rule idea (pseudo-query)EventID=4769 WITHOUT preceding EventID=4768 for same user (10h window)
  • AdminSDHolder ACLT1098

    ACL change on AdminSDHolder

    Rule idea (pseudo-query)EventID=5136 AND ObjectDN CONTAINS "CN=AdminSDHolder"

Rules are a starting point. Adapt them to Splunk / Sentinel / Elastic fields and test against your own baseline.