MITRE ATT&CK matrix for AD
Every attack on this site → its MITRE technique → which events reveal it → a SIEM detection rule idea.
Go to attack cardsDiscovery
TA0007
- BloodHound / SharpHoundT1087.002
Mass LDAP queries
Rule idea (pseudo-query)
LDAP queries > N/min from one host (Event 1644)
Credential Access
TA0006
- AS-REP RoastingT1558.004
TGT without pre-auth
Rule idea (pseudo-query)
EventID=4768 AND PreAuthType=0 - KerberoastingT1558.003
RC4 service ticket for a user account
Rule idea (pseudo-query)
EventID=4769 AND TicketEncryptionType=0x17 AND ServiceName!="*$" - NTLM RelayT1557.001
IP does not match the workstation
Rule idea (pseudo-query)
EventID=4624 AND AuthenticationPackageName=NTLM AND IpAddress NOT IN known_hosts(WorkstationName) - DCSyncT1003.006
Replication from a non-DC account
Rule idea (pseudo-query)
EventID=4662 AND Properties CONTAINS "1131f6aa" AND SubjectUserName!="*$" - Password SprayingT1110.003
One IP, many users
Rule idea (pseudo-query)
EventID IN (4625,4771) | distinct TargetUserName by IpAddress > 10 in 30m
Privilege Escalation
TA0004
Lateral Movement
TA0008
- Pass-the-HashT1550.002
NTLM logon without a real password
Rule idea (pseudo-query)
EventID=4624 AND (LogonType=9 OR (LogonType=3 AND LmPackageName="NTLM V2" AND KeyLength=0))
Persistence
TA0003
Rules are a starting point. Adapt them to Splunk / Sentinel / Elastic fields and test against your own baseline.